CVE-2026-0403
published 2026-01-13CVE-2026-0403: An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.
PriorityP348high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
0.29%
21.3th percentile
An insufficient input validation vulnerability in NETGEAR Orbi routers
allows attackers connected to the router's LAN to execute OS command
injections.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | rbe970 | < v9.10.0.2 | v9.10.0.2 |
| netgear | rbe970_firmware | < 9.10.0.2 | 9.10.0.2 |
| netgear | rbe971 | < v9.10.0.2 | v9.10.0.2 |
| netgear | rbe971_firmware | < 9.10.0.2 | 9.10.0.2 |
| netgear | rbr750 | <= 4.6.14.3 | — |
| netgear | rbr750_firmware | < 7.2.8.5 | 7.2.8.5 |
| netgear | rbr850 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbr850_firmware | < 7.2.8.5 | 7.2.8.5 |
| netgear | rbr860 | < v7.2.8.5 | v7.2.8.5 |
| netgear | rbr860_firmware | < 7.2.8.5 | 7.2.8.5 |
| netgear | rbre960 | < v7.2.7.15 | v7.2.7.15 |
| netgear | rbre960_firmware | < 7.2.8.5 | 7.2.8.5 |
| netgear | rbs750 | <= 4.6.14.3 | — |
| netgear | rbs750_firmware | < 7.2.8.5 | 7.2.8.5 |
| netgear | rbs850 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbs850_firmware | < 7.2.8.5 | 7.2.8.5 |
| netgear | rbs860 | < v7.2.8.5 | v7.2.8.5 |
| netgear | rbs860_firmware | < 7.2.8.5 | 7.2.8.5 |
| netgear | rbse960 | < v7.2.7.15 | v7.2.7.15 |
| netgear | rbse960_firmware | < 7.2.8.5 | 7.2.8.5 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.01.1LOWCVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/rbe970https://www.netgear.com/support/product/rbe971https://www.netgear.com/support/product/rbr750https://www.netgear.com/support/product/rbr850https://www.netgear.com/support/product/rbr860https://www.netgear.com/support/product/rbre960https://www.netgear.com/support/product/rbs750https://www.netgear.com/support/product/rbs850https://www.netgear.com/support/product/rbs860https://www.netgear.com/support/product/rbse960
2026-01-13
Published