CVE-2026-0403

An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:rbe971_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe971:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:rbe970_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe970:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:rbr860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr860:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netgear:rbs860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs860:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netgear:rbre960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbre960:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netgear:rbse960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbse960:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 16:16

Updated : 2026-02-20 19:38


NVD link : CVE-2026-0403

Mitre link : CVE-2026-0403

CVE.ORG link : CVE-2026-0403


JSON object : View

Products Affected

netgear

  • rbr750_firmware
  • rbr860
  • rbe971
  • rbse960
  • rbre960_firmware
  • rbs750
  • rbr860_firmware
  • rbr750
  • rbe971_firmware
  • rbre960
  • rbs860
  • rbr850
  • rbs860_firmware
  • rbe970_firmware
  • rbs750_firmware
  • rbs850
  • rbe970
  • rbs850_firmware
  • rbr850_firmware
  • rbse960_firmware
CWE
CWE-20

Improper Input Validation