cbcvebase.
CVE-2026-0417
published 2026-06-09

CVE-2026-0417: Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the…

PriorityP423medium4.3CVSS 4.0
AVAACLATNPRHUINVCNVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVDRELUAmber
EPSS
0.23%
13.7th percentile
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
netgearmr60< V1.1.7.132V1.1.7.132
netgearmr70< V1.0.3.28V1.0.3.28
netgearmr80< V1.1.7.14V1.1.7.14
netgearms60< V1.1.7.132V1.1.7.132
netgearms70< V1.0.3.28V1.0.3.28
netgearms80< V1.1.7.14V1.1.7.14
netgearr6400v2< V1.0.4.128V1.0.4.128
netgearr6700v3< V1.0.4.128V1.0.4.128
netgearr6900p< V1.3.3.152V1.3.3.152
netgearr7000< V1.0.11.216V1.0.11.216
netgearr7000p< V1.3.3.152V1.3.3.152
netgearr7960p< V1.4.4.92V1.4.4.92
netgearr8000p< V1.4.4.92V1.4.4.92
netgearr8500<= 1.0.2.160
netgearrax20< V1.0.18.144V1.0.18.144
netgearrax35v2< V1.0.16.132V1.0.16.132
netgearrax40v2< V1.0.12.118V1.0.12.118
netgearrax41< V1.0.12.118V1.0.12.118
netgearrax42< V1.0.12.118V1.0.12.118
netgearrax43< V1.0.12.120V1.0.12.120
netgearrax45< V1.0.12.118V1.0.12.118
netgearrax48< V1.0.12.118V1.0.12.118
netgearrax50< V1.0.12.120V1.0.12.120
netgearrax50s< V1.0.12.120V1.0.12.120
netgearraxe450< V1.0.10.86V1.0.10.86
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.