Executive brief
A vulnerability in several Netgear Orbi router models allows an attacker on the local network to crash the device. This results in a loss of internet connectivity and network services for all connected users. An attacker does not need a password to trigger this disruption, potentially impacting business operations or home connectivity.
Technical details
A denial-of-service vulnerability exists in multiple Netgear router models (RBR860, RBRE950, RBRE960, RBS860, RBSE950, RBSE960) due to an out-of-bounds write (CWE-787). An unauthenticated attacker located on the same local network (adjacent) can exploit this by sending specially crafted requests to the device. Successful exploitation leads to a crash or hang, rendering the router unavailable. The vulnerability is tracked as CVE-2026-3088 and has been assigned a CVSS 4.0 score of 4.9 by the vendor.
Affected products
- Netgear RBR860
- Netgear RBRE950
- Netgear RBRE960
- Netgear RBS860
- Netgear RBSE950
- Netgear RBSE960
Timeline
- 2026-06-09: disclosed: CVE published to NVD dataset