CVE-2026-0416
published 2026-06-09CVE-2026-0416: An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to…
PriorityP422medium4.3CVSS 4.0
AVAACLATNPRHUINVCNVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVDRELUAmber
EPSS
0.18%
7.6th percentile
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | raxe450 | >= V1.0.12.96 < V1.2.14.114 | V1.2.14.114 |
| netgear | raxe500 | >= V1.0.12.96 < V1.2.14.114 | V1.2.14.114 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Netgear RAXE450/RAXE500 1.0.11.216 Standard Management Interface input validation
vuldb·2026-06-09·CVSS 4.3
CVE-2026-0416 [MEDIUM] Netgear RAXE450/RAXE500 1.0.11.216 Standard Management Interface input validation
A vulnerability marked as problematic has been reported in Netgear RAXE450 and RAXE500 1.0.11.216. This impacts an unknown function of the component Standard Management Interface. This manipulation causes improper input validation.
This vulnerability is handled as CVE-2026-0416. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
Authenticated administrators connected to the local network can modify router functionality beyond what is intended through the standard management interface.
ghsa_unreviewed·2026-06-09
CVE-2026-0416 [MEDIUM] CWE-20 Authenticated administrators connected to the local network can modify router functionality beyond what is intended through the standard management interface.
Authenticated administrators connected to the local network can modify router functionality beyond what is intended through the standard management interface.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-09
Published