Junglewise Threat Intelligence

CVE-2026-0419: NETGEAR JR6150 OS command injection via improper input validation

CVE-2026-0419 · Severity: info · CVSS 4.4 · Published 2026-06-09

Vendors: NETGEAR.

Executive brief

A security vulnerability exists in the NETGEAR JR6150 router, a device used to provide wireless internet access in homes and small offices. An individual already connected to the local WiFi network could exploit this flaw to take control of the router's operating system. Because this product reached its end-of-life in 2018, no security patches will be released, and the manufacturer recommends replacing the hardware to maintain security.

Technical details

The vulnerability is classified as improper input validation (CWE-20) within the firmware of the NETGEAR JR6150 AC750 router. An attacker with local network access and low-level privileges can bypass validation checks to perform OS command injection. This allows for full compromise of the device's confidentiality, integrity, and availability. The flaw was discovered via firmware emulation and has not been verified on physical hardware. As the device reached End-of-Support (EoS) in 2018, no official patch is available; the vendor recommends decommissioning the affected hardware.

Affected products

  • NETGEAR JR6150 (AC750 WiFi Router) All versions (End-of-Support)

Timeline

  • 2018: other: Product reached End-of-Support phase
  • 2026-06-09: disclosed: Vulnerability published by Netgear and NVD

References

Related threats