Executive brief
A security flaw in NETGEAR Orbi mesh WiFi systems could allow a person already connected to your home or office network to gain full administrative control over the router. This vulnerability specifically affects systems using satellite extenders; standalone Orbi routers are not impacted. An attacker with this level of access could change network settings, monitor traffic, or disrupt internet connectivity.
Technical details
An information disclosure vulnerability (CWE-200) exists in the communication or configuration handling of NETGEAR Orbi satellite devices. An attacker with low-privileged access to the adjacent network (WiFi or Ethernet) can exploit this flaw to retrieve sensitive information that facilitates full administrative access to the primary Orbi router. The issue is specific to mesh configurations involving satellite units; standalone Orbi WiFi systems are not affected. The vulnerability has been assigned a CVSS 4.0 score of 4.2 by the vendor, reflecting that while the impact on confidentiality and subsequent system integrity is high, it requires prior network access.
Affected products
- NETGEAR Orbi RBE970
- NETGEAR Orbi RBR350
- NETGEAR Orbi RBR760
- NETGEAR Orbi RBS350
- NETGEAR Orbi RBS760
Timeline
- 2026-06-09: disclosed: Initial publication of CVE-2026-0411
- 2026-06-09: advisory