CVE-2026-0404

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:rbr840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr840:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:rbr860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr860:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netgear:rbs840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs840:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netgear:rbs860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs860:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netgear:rbre950_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbre950:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netgear:rbre960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbre960:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:netgear:rbse950_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbse950:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:netgear:rbse960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbse960:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 16:16

Updated : 2026-02-12 17:36


NVD link : CVE-2026-0404

Mitre link : CVE-2026-0404

CVE.ORG link : CVE-2026-0404


JSON object : View

Products Affected

netgear

  • rbr750_firmware
  • rbr860
  • rbse960
  • rbre960_firmware
  • rbre950
  • rbs750
  • rbse950
  • rbr860_firmware
  • rbr750
  • rbr840_firmware
  • rbr840
  • rbre960
  • rbs840
  • rbs860
  • rbr850
  • rbs840_firmware
  • rbs860_firmware
  • rbre950_firmware
  • rbs750_firmware
  • rbs850
  • rbse950_firmware
  • rbs850_firmware
  • rbr850_firmware
  • rbse960_firmware
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo