CVE-2026-0417
published 2026-06-09CVE-2026-0417: Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the…
PriorityP423medium4.3CVSS 4.0
AVAACLATNPRHUINVCNVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVDRELUAmber
EPSS
0.23%
13.7th percentile
Insufficient input validation vulnerability in the listed NETGEAR devices allows
authenticated administrators connected to the local network to tamper with
the router's integrity.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | mr60 | < V1.1.7.132 | V1.1.7.132 |
| netgear | mr70 | < V1.0.3.28 | V1.0.3.28 |
| netgear | mr80 | < V1.1.7.14 | V1.1.7.14 |
| netgear | ms60 | < V1.1.7.132 | V1.1.7.132 |
| netgear | ms70 | < V1.0.3.28 | V1.0.3.28 |
| netgear | ms80 | < V1.1.7.14 | V1.1.7.14 |
| netgear | r6400v2 | < V1.0.4.128 | V1.0.4.128 |
| netgear | r6700v3 | < V1.0.4.128 | V1.0.4.128 |
| netgear | r6900p | < V1.3.3.152 | V1.3.3.152 |
| netgear | r7000 | < V1.0.11.216 | V1.0.11.216 |
| netgear | r7000p | < V1.3.3.152 | V1.3.3.152 |
| netgear | r7960p | < V1.4.4.92 | V1.4.4.92 |
| netgear | r8000p | < V1.4.4.92 | V1.4.4.92 |
| netgear | r8500 | <= 1.0.2.160 | — |
| netgear | rax20 | < V1.0.18.144 | V1.0.18.144 |
| netgear | rax35v2 | < V1.0.16.132 | V1.0.16.132 |
| netgear | rax40v2 | < V1.0.12.118 | V1.0.12.118 |
| netgear | rax41 | < V1.0.12.118 | V1.0.12.118 |
| netgear | rax42 | < V1.0.12.118 | V1.0.12.118 |
| netgear | rax43 | < V1.0.12.120 | V1.0.12.120 |
| netgear | rax45 | < V1.0.12.118 | V1.0.12.118 |
| netgear | rax48 | < V1.0.12.118 | V1.0.12.118 |
| netgear | rax50 | < V1.0.12.120 | V1.0.12.120 |
| netgear | rax50s | < V1.0.12.120 | V1.0.12.120 |
| netgear | raxe450 | < V1.0.10.86 | V1.0.10.86 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Netgear XR1000 prior 1.1.7.132 input validation
vuldb·2026-06-09·CVSS 4.3
CVE-2026-0417 [MEDIUM] Netgear XR1000 prior 1.1.7.132 input validation
A vulnerability described as problematic has been identified in Netgear MR60, MR70, MR80, MS60, MS70, MS80, R6400v2, R6700v3, R6900P, R7000, R7000P, R7960P, R8000P, R8500, RAX20, RAX35v2, RAX40v2, RAX41, RAX42, RAX43, RAX45, RAX48, RAX50, RAX50S, RAXE450, RAXE500 and XR1000. Affected is an unknown function. Such manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2026-0417. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.
GHSA
Insufficient input validation vulnerability in NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
ghsa_unreviewed·2026-06-09
CVE-2026-0417 [MEDIUM] CWE-20 Insufficient input validation vulnerability in NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
Insufficient input validation vulnerability in NETGEAR devices allows
authenticated administrators connected to the local network to tamper with
the router's integrity.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/mr60/https://www.netgear.com/support/product/mr70/https://www.netgear.com/support/product/mr80/https://www.netgear.com/support/product/ms60/https://www.netgear.com/support/product/ms70/https://www.netgear.com/support/product/ms80/https://www.netgear.com/support/product/r6400v2/https://www.netgear.com/support/product/r6700v3/https://www.netgear.com/support/product/r6900p/https://www.netgear.com/support/product/r7000/https://www.netgear.com/support/product/r7000p/https://www.netgear.com/support/product/r7960p/https://www.netgear.com/support/product/r8000p/https://www.netgear.com/support/product/r8500/https://www.netgear.com/support/product/rax20/https://www.netgear.com/support/product/rax35v2/https://www.netgear.com/support/product/rax40v2/https://www.netgear.com/support/product/rax41/https://www.netgear.com/support/product/rax42/https://www.netgear.com/support/product/rax43/https://www.netgear.com/support/product/rax45/https://www.netgear.com/support/product/rax48/https://www.netgear.com/support/product/rax50/https://www.netgear.com/support/product/rax50s/https://www.netgear.com/support/product/raxe450/https://www.netgear.com/support/product/raxe500/https://www.netgear.com/support/product/xr1000/
2026-06-09
Published