Junglewise Threat Intelligence

CVE-2026-0413: NETGEAR Multiple Router Models stack-based buffer overflow

CVE-2026-0413 · Severity: info · CVSS 4.3 · Published 2026-06-09

Technologies: NETGEAR RBS860, NETGEAR RBR860, NETGEAR RBR840, NETGEAR RBS850, NETGEAR RBS840, NETGEAR RBS750, NETGEAR RBRE960, NETGEAR RBSE950, NETGEAR RBRE950, NETGEAR RBSE960, NETGEAR RBR850, NETGEAR RBR750. Vendors: NETGEAR.

Executive brief

A security vulnerability exists in several NETGEAR router models that could allow an authorized administrator to modify the device's core software. To exploit this, an attacker would already need administrative credentials and access to the local network. If successful, they could make unauthorized changes to how the router functions or alter its internal software.

Technical details

A stack-based buffer overflow (CWE-121) exists in multiple NETGEAR router models due to insufficient input validation of buffers. The vulnerability is accessible to authenticated administrators connected via the local network (adjacent attack vector). An attacker with high privileges can exploit this flaw to achieve unauthorized modification of the router's firmware or software functionality. The CVSS 4.0 score is 4.3, reflecting that while the impact on integrity is high, it requires significant prior authentication and local network proximity.

Affected products

  • NETGEAR RBE372
  • NETGEAR RBE770
  • NETGEAR RBR750
  • NETGEAR RBR840
  • NETGEAR RBR850
  • NETGEAR RBR860
  • NETGEAR RBRE950
  • NETGEAR RBRE960
  • NETGEAR RBS750
  • NETGEAR RBS840
  • NETGEAR RBS850
  • NETGEAR RBS860
  • NETGEAR RBSE950
  • NETGEAR RBSE960

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats