CVE-2026-0407
published 2026-01-13CVE-2026-0407: An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet…
medium6.1CVSS 4.0
AVAACLATNPRLUINVCHVIHVAHSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUNRUVDREMUAmber
An insufficient authentication vulnerability in NETGEAR WiFi range
extenders allows a network adjacent attacker with WiFi authentication or
a physical Ethernet port connection to bypass the authentication
process and access the admin panel.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | ex2800 | < v1.0.1.82 | v1.0.1.82 |
| netgear | ex2800_firmware | < 1.0.1.82 | 1.0.1.82 |
| netgear | ex3110 | < v1.0.1.82 | v1.0.1.82 |
| netgear | ex3110_firmware | < 1.0.1.82 | 1.0.1.82 |
| netgear | ex5000 | < v1.0.1.82 | v1.0.1.82 |
| netgear | ex5000_firmware | < 1.0.1.82 | 1.0.1.82 |
| netgear | ex6110 | < v1.0.1.82 | v1.0.1.82 |
| netgear | ex6110_firmware | < 1.0.1.82 | 1.0.1.82 |