Executive brief
A security vulnerability exists in the NETGEAR JR6150 router, an older home networking device. An attacker with administrative access on the local network could exploit this flaw to make unauthorized changes to the router's software and core functions. Because this product reached its end-of-life in 2018, no security patches will be released, and users are advised to replace the hardware to maintain a secure network.
Technical details
This vulnerability is classified as improper input validation (CWE-20) within the firmware of the NETGEAR JR6150 router. An attacker must have administrative privileges and be connected to the local network (adjacent) to exploit the flaw. Successful exploitation allows for the unauthorized modification of router software and system functionality. The vulnerability was identified via firmware emulation and has not been verified on physical hardware. As the device reached End-of-Support (EoS) in 2018, no official patch is available, and the vendor recommends hardware replacement.
Affected products
- NETGEAR JR6150 (AC750 WiFi Router) All versions (End-of-Support)
Timeline
- 2026-06-09: advisory: Initial disclosure by NETGEAR and NVD publication.