CVE-2026-0415
- EPSS 0.23%
- Veröffentlicht 09.06.2026 15:50:51
- Zuletzt bearbeitet 23.07.2026 08:10:00
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
CVE-2026-0413
- EPSS 0.32%
- Veröffentlicht 09.06.2026 15:50:50
- Zuletzt bearbeitet 23.07.2026 08:10:00
A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
CVE-2026-0418
- EPSS 0.25%
- Veröffentlicht 09.06.2026 15:50:50
- Zuletzt bearbeitet 23.07.2026 08:10:00
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
- EPSS 0.31%
- Veröffentlicht 13.01.2026 16:16:10
- Zuletzt bearbeitet 20.02.2026 19:38:39
An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.
- EPSS 1.12%
- Veröffentlicht 13.01.2026 16:16:10
- Zuletzt bearbeitet 12.02.2026 17:36:09
An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.
CVE-2026-0405
- EPSS 0.35%
- Veröffentlicht 13.01.2026 16:16:10
- Zuletzt bearbeitet 12.02.2026 17:40:40
An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.
CVE-2022-37337
- EPSS 2.83%
- Veröffentlicht 21.03.2023 18:15:12
- Zuletzt bearbeitet 21.11.2024 07:14:47
A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigge...
CVE-2022-38452
- EPSS 2.11%
- Veröffentlicht 21.03.2023 18:15:12
- Zuletzt bearbeitet 21.11.2024 07:16:30
A command execution vulnerability exists in the hidden telnet service functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger ...
CVE-2022-38458
- EPSS 0.61%
- Veröffentlicht 21.03.2023 18:15:12
- Zuletzt bearbeitet 21.11.2024 07:16:31
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information.
CVE-2022-36429
- EPSS 1.99%
- Veröffentlicht 21.03.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:12:59
A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A specially-crafted JSON object can lead to arbitrary command execution. An attacker can send a sequence of malicious ...