CVE-2026-0405

An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.
References
Link Resource
https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory Patch Vendor Advisory
https://www.netgear.com/support/product/cbr750 Patch Product
https://www.netgear.com/support/product/nbr750 Patch Product
https://www.netgear.com/support/product/rbe370 Patch Product
https://www.netgear.com/support/product/rbe371 Patch Product
https://www.netgear.com/support/product/rbe372 Patch Product
https://www.netgear.com/support/product/rbe373 Patch Product
https://www.netgear.com/support/product/rbe374 Patch Product
https://www.netgear.com/support/product/rbe770 Patch Product
https://www.netgear.com/support/product/rbe771 Patch Product
https://www.netgear.com/support/product/rbe772 Patch Product
https://www.netgear.com/support/product/rbe773 Patch Product
https://www.netgear.com/support/product/rbe970 Patch Product
https://www.netgear.com/support/product/rbe971 Patch Product
https://www.netgear.com/support/product/rbr750 Patch Product
https://www.netgear.com/support/product/rbr840 Patch Product
https://www.netgear.com/support/product/rbr850 Patch Product
https://www.netgear.com/support/product/rbr860 Patch Product
https://www.netgear.com/support/product/rbre950 Patch Product
https://www.netgear.com/support/product/rbre960 Patch Product
https://www.netgear.com/support/product/rbs750 Patch Product
https://www.netgear.com/support/product/rbs840 Patch Product
https://www.netgear.com/support/product/rbs850 Patch Product
https://www.netgear.com/support/product/rbs860 Patch Product
https://www.netgear.com/support/product/rbse950 Patch Product
https://www.netgear.com/support/product/rbse960 Patch Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:cbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:cbr750:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:nbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:nbr750:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:rbe370_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe370:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:rbe371_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe371:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:rbe372_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe372:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netgear:rbe373_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe373:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netgear:rbe374_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe374:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netgear:rbe770_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe770:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netgear:rbe771_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe771:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netgear:rbe772_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe772:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:netgear:rbe773_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe773:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:netgear:rbe970_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe970:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:netgear:rbe971_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbe971:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:netgear:rbr840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr840:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:netgear:rbr860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr860:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:netgear:rbs840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs840:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:netgear:rbs860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs860:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:netgear:rbre950_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbre950:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:netgear:rbre960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbre960:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:netgear:rbse950_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbse950:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:netgear:rbse960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbse960:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 16:16

Updated : 2026-02-12 17:40


NVD link : CVE-2026-0405

Mitre link : CVE-2026-0405

CVE.ORG link : CVE-2026-0405


JSON object : View

Products Affected

netgear

  • rbr750_firmware
  • cbr750
  • rbe770_firmware
  • rbe371
  • rbe373_firmware
  • nbr750
  • rbr860
  • rbe971
  • rbse960
  • rbe772
  • rbre960_firmware
  • rbre950
  • rbs750
  • rbse950
  • rbr860_firmware
  • rbr750
  • rbe971_firmware
  • rbe373
  • rbr840_firmware
  • rbe770
  • rbr840
  • rbre960
  • rbe371_firmware
  • rbs840
  • rbe372_firmware
  • rbs860
  • rbr850
  • rbs840_firmware
  • rbe370
  • rbs860_firmware
  • rbe970_firmware
  • rbre950_firmware
  • rbe370_firmware
  • rbs750_firmware
  • rbe773
  • rbs850
  • rbse950_firmware
  • rbe970
  • rbe374
  • rbe372
  • rbe771_firmware
  • rbs850_firmware
  • cbr750_firmware
  • rbe773_firmware
  • rbe772_firmware
  • nbr750_firmware
  • rbe374_firmware
  • rbr850_firmware
  • rbe771
  • rbse960_firmware
CWE
CWE-287

Improper Authentication

NVD-CWE-noinfo