Executive brief
A security vulnerability has been identified in several NETGEAR Orbi WiFi router and satellite models. An attacker could exploit this flaw to cause the device to crash or restart unexpectedly, leading to a loss of internet connectivity for all connected users. This disruption can impact business operations and remote work by making the local network temporarily unavailable.
Technical details
A stack-based buffer overflow (CWE-121) exists in multiple NETGEAR Orbi models, including the RBR and RBS series. The vulnerability allows an unauthenticated attacker with adjacent network access to trigger a denial-of-service (DoS) condition, causing the device to hang or reboot. According to the CVSS 4.0 vector, the attack requires no special privileges or user interaction. NETGEAR has released firmware updates (V7.2.7.15 and V9.10.1.4 depending on the model) to address this issue.
Affected products
- NETGEAR RBR860 < V7.2.7.15
- NETGEAR RBRE950 < v7.2.7.15
- NETGEAR RBRE960 < V7.2.7.15
- NETGEAR RBE970 < V9.10.1.4
- NETGEAR RBE971 < V9.10.1.4
- NETGEAR RBS860 < V7.2.7.15
- NETGEAR RBSE950 < v7.2.7.15
- NETGEAR RBSE960 < V7.2.7.15
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory