CVE-2026-0418
published 2026-06-09CVE-2026-0418: Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
PriorityP424medium4.3CVSS 4.0
AVAACLATNPRHUINVCNVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRUVDRELUAmber
EPSS
0.24%
15.6th percentile
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | cbr750 | < v4.6.14.4 | v4.6.14.4 |
| netgear | ex6120 | <= 1.0.0.72 | — |
| netgear | ex6130 | <= 1.0.0.54 | — |
| netgear | mr60 | < V1.1.7.128 | V1.1.7.128 |
| netgear | mr70 | < V1.0.3.28 | V1.0.3.28 |
| netgear | mr80 | < V1.1.7.6 | V1.1.7.6 |
| netgear | ms60 | < V1.1.7.128 | V1.1.7.128 |
| netgear | ms70 | < V1.0.3.28 | V1.0.3.28 |
| netgear | ms80 | < V1.1.7.6 | V1.1.7.6 |
| netgear | rax15 | <= 1.0.18.144 | — |
| netgear | rax20 | <= 1.0.18.144 | — |
| netgear | rax200 | <= 1.0.11.148 | — |
| netgear | rax35v2 | < V1.0.11.112 | V1.0.11.112 |
| netgear | rax38v2 | < V1.0.11.112 | V1.0.11.112 |
| netgear | rax40v2 | < V1.0.11.112 | V1.0.11.112 |
| netgear | rax42 | < V1.0.11.112 | V1.0.11.112 |
| netgear | rax43 | < V1.0.11.112 | V1.0.11.112 |
| netgear | rax45 | < V1.0.11.112 | V1.0.11.112 |
| netgear | rax48 | < V1.0.11.112 | V1.0.11.112 |
| netgear | rax50 | < V1.0.11.112 | V1.0.11.112 |
| netgear | rax50s | < V1.0.11.112 | V1.0.11.112 |
| netgear | rax75 | <= 1.0.11.148 | — |
| netgear | rax80 | <= 1.0.11.148 | — |
| netgear | raxe450 | < V1.0.10.86 | V1.0.10.86 |
| netgear | raxe500 | < V1.0.10.86 | V1.0.10.86 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Netgear XR1000 prior 4.6.14.4 Configuration external control of setting
vuldb·2026-06-09·CVSS 4.3
CVE-2026-0418 [MEDIUM] Netgear XR1000 prior 4.6.14.4 Configuration external control of setting
A vulnerability classified as problematic has been found in Netgear CBR750, EX6120, EX6130, MR60, MR70, MR80, MS60, MS70, MS80, RAX15, RAX20, RAX200, RAX35v2, RAX38v2, RAX40v2, RAX42, RAX43, RAX45, RAX48, RAX50, RAX50S, RAX75, RAX80, RAXE450, RAXE500, RBR750, RBR840, RBR850, RBRE960, RBS750, RBS840, RBS850, RBSE960, RS700 and XR1000. Affected by this vulnerability is an unknown functionality of the component Configuration Handler. Performing a manipulation results in external control of system or configuration setting.
This vulnerability was named CVE-2026-0418. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
ghsa_unreviewed·2026-06-09
CVE-2026-0418 [MEDIUM] CWE-15 Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/cbr750/https://www.netgear.com/support/product/ex6120/https://www.netgear.com/support/product/ex6130/https://www.netgear.com/support/product/mr60/https://www.netgear.com/support/product/mr70/https://www.netgear.com/support/product/mr80/https://www.netgear.com/support/product/ms60/https://www.netgear.com/support/product/ms70/https://www.netgear.com/support/product/ms80/https://www.netgear.com/support/product/rax15/https://www.netgear.com/support/product/rax20/https://www.netgear.com/support/product/rax200/https://www.netgear.com/support/product/rax35v2/https://www.netgear.com/support/product/rax38v2/https://www.netgear.com/support/product/rax40v2/https://www.netgear.com/support/product/rax42/https://www.netgear.com/support/product/rax43/https://www.netgear.com/support/product/rax45/https://www.netgear.com/support/product/rax48/https://www.netgear.com/support/product/rax50/https://www.netgear.com/support/product/rax50s/https://www.netgear.com/support/product/rax75/https://www.netgear.com/support/product/rax80/https://www.netgear.com/support/product/raxe450/https://www.netgear.com/support/product/raxe500/https://www.netgear.com/support/product/rbr750/https://www.netgear.com/support/product/rbr840/https://www.netgear.com/support/product/rbr850/https://www.netgear.com/support/product/rbre960/https://www.netgear.com/support/product/rbs750/https://www.netgear.com/support/product/rbs840/https://www.netgear.com/support/product/rbs850/https://www.netgear.com/support/product/rbse960/https://www.netgear.com/support/product/rs700/https://www.netgear.com/support/product/xr1000/
2026-06-09
Published