CVE-2026-0411
published 2026-06-09CVE-2026-0411: An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator…
PriorityP346high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
0.28%
20.0th percentile
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.
Orbi WiFi Systems without satellite devices are not impacted by this issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | rbe970 | < 6.3.8.11 | 6.3.8.11 |
| netgear | rbe970_firmware | < 9.13.2.1 | 9.13.2.1 |
| netgear | rbr350 | < V4.4.2.2 | V4.4.2.2 |
| netgear | rbr350_firmware | < 4.4.2.2 | 4.4.2.2 |
| netgear | rbr760 | < V6.3.8.11 | V6.3.8.11 |
| netgear | rbr760_firmware | < 6.3.8.11 | 6.3.8.11 |
| netgear | rbs350 | < V4.4.2.2 | V4.4.2.2 |
| netgear | rbs350_firmware | < 4.4.2.2 | 4.4.2.2 |
| netgear | rbs760 | < V6.3.8.11 | V6.3.8.11 |
| netgear | rbs760_firmware | < 6.3.8.11 | 6.3.8.11 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.04.2MEDIUMCVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Netgear RBE97x/RBR350/RBR760/RBS350/RBS760 prior 6.3.8.11 information disclosure
vuldb·2026-06-21·CVSS 4.2
CVE-2026-0411 [MEDIUM] Netgear RBE97x/RBR350/RBR760/RBS350/RBS760 prior 6.3.8.11 information disclosure
A vulnerability marked as problematic has been reported in Netgear RBE97x, RBR350, RBR760, RBS350 and RBS760. Impacted is an unknown function. This manipulation causes information disclosure.
This vulnerability appears as CVE-2026-0411. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
An information disclosure vulnerability in the NETGEAR Orbi satellites could allow a user connected to your network to gain administrator access to the Orbi router.
ghsa_unreviewed·2026-06-09
CVE-2026-0411 [MEDIUM] CWE-200 An information disclosure vulnerability in the NETGEAR Orbi satellites could allow a user connected to your network to gain administrator access to the Orbi router.
An information disclosure vulnerability in the NETGEAR Orbi satellites could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.
Orbi WiFi Systems without satellite devices are not impacted by this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/rbe970/https://www.netgear.com/support/product/rbr350/https://www.netgear.com/support/product/rbr760/https://www.netgear.com/support/product/rbs350/https://www.netgear.com/support/product/rbs760/
2026-06-09
Published