cbcvebase.
CVE-2026-0410
published 2026-06-09

CVE-2026-0410: Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and…

PriorityP412low1.9CVSS 4.0
AVAACHATNPRHUINVCNVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVDRELUAmber
EPSS
0.22%
12.3th percentile
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.

Affected

20 ranges
VendorProductVersion rangeFixed in
netgearr7000< V1.0.11.216V1.0.11.216
netgearrax20< V1.0.18.144V1.0.18.144
netgearrax35v2< V1.0.16.132V1.0.16.132
netgearrax41< V1.0.16.132V1.0.16.132
netgearrax41v2< V1.1.4.28V1.1.4.28
netgearrax42< V1.0.16.132V1.0.16.132
netgearrax42v2< V1.1.4.28V1.1.4.28
netgearrax43< V1.0.16.132V1.0.16.132
netgearrax43v2< V1.1.4.28V1.1.4.28
netgearrax45< V1.0.16.132V1.0.16.132
netgearrax49s< V1.1.4.28V1.1.4.28
netgearrax50< V1.0.16.132V1.0.16.132
netgearrax50s< V1.0.16.132V1.0.16.132
netgearrax50v2< V1.1.4.28V1.1.4.28
netgearrax54sv2< V1.1.4.28V1.1.4.28
netgearrax54v2< V1.1.4.28V1.1.4.28
netgearraxe450< V1.2.14.114V1.2.14.114
netgearraxe500< V1.2.14.114V1.2.14.114
netgearxr1000< V1.1.0.22V1.1.0.22
netgearxr1000v2< V1.1.0.22V1.1.0.22
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.