cbcvebase.
CVE-2026-0403
published 2026-01-13

CVE-2026-0403: An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

low1.1CVSS 4.0
AVAACLATNPRHUINVCNVILVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUNRUVDREMUAmber
An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

Affected

20 ranges
VendorProductVersion rangeFixed in
netgearrbe970< v9.10.0.2v9.10.0.2
netgearrbe970_firmware< 9.10.0.29.10.0.2
netgearrbe971< v9.10.0.2v9.10.0.2
netgearrbe971_firmware< 9.10.0.29.10.0.2
netgearrbr750<= 4.6.14.3
netgearrbr750_firmware< 7.2.8.57.2.8.5
netgearrbr850< V7.2.8.5V7.2.8.5
netgearrbr850_firmware< 7.2.8.57.2.8.5
netgearrbr860< v7.2.8.5v7.2.8.5
netgearrbr860_firmware< 7.2.8.57.2.8.5
netgearrbre960< v7.2.7.15v7.2.7.15
netgearrbre960_firmware< 7.2.8.57.2.8.5
netgearrbs750<= 4.6.14.3
netgearrbs750_firmware< 7.2.8.57.2.8.5
netgearrbs850< V7.2.8.5V7.2.8.5
netgearrbs850_firmware< 7.2.8.57.2.8.5
netgearrbs860< v7.2.8.5v7.2.8.5
netgearrbs860_firmware< 7.2.8.57.2.8.5
netgearrbse960< v7.2.7.15v7.2.7.15
netgearrbse960_firmware< 7.2.8.57.2.8.5