Executive brief
A security vulnerability exists in several NETGEAR router models that could allow an authorized administrator to make unauthorized changes to the device's software. To exploit this, an attacker would already need administrative credentials and be connected to the local network. This could lead to the modification of router functionality or the installation of unauthorized software updates.
Technical details
An improper input validation vulnerability (CWE-20) exists in the management interface of various NETGEAR router models. The flaw allows an attacker with high privileges (administrative access) and adjacent network access (local network) to bypass intended restrictions and modify the device's software or core functionality. While the exploit requires existing authentication, it allows for integrity violations that should normally be restricted even for administrative users. The vulnerability is tracked via CVSS 4.0 with a base score of 4.3, reflecting the high privilege requirement and lack of direct impact on confidentiality or availability.
Affected products
- NETGEAR RBE970
- NETGEAR RBR750
- NETGEAR RBR840
- NETGEAR RBR850
- NETGEAR RBR860
- NETGEAR RBRE950
- NETGEAR RBRE960
- NETGEAR RBS750
- NETGEAR RBS840
- NETGEAR RBS850
- NETGEAR RBS860
- NETGEAR RBSE950
- NETGEAR RBSE960
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
References
- https://www.netgear.com/support/product/rbe970/
- https://www.netgear.com/support/product/rbr750/
- https://www.netgear.com/support/product/rbr840/
- https://www.netgear.com/support/product/rbr850/
- https://www.netgear.com/support/product/rbr860/
- https://www.netgear.com/support/product/rbre950/
- https://www.netgear.com/support/product/rbre960/