cbcvebase.
CVE-2026-0418
published 2026-06-09

CVE-2026-0418: Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

PriorityP424medium4.5CVSS 3.1
AVAACLPRHUINSUCNIHAN
EPSS
0.24%
15.6th percentile
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
netgearcbr750< v4.6.14.4v4.6.14.4
netgearcbr750_firmware< 4.6.14.44.6.14.4
netgearex6120<= 1.0.0.72
netgearex6130<= 1.0.0.54
netgearmr60< V1.1.7.128V1.1.7.128
netgearmr60_firmware< 1.1.7.1281.1.7.128
netgearmr70< V1.0.3.28V1.0.3.28
netgearmr70_firmware< 1.0.3.281.0.3.28
netgearmr80< V1.1.7.6V1.1.7.6
netgearmr80_firmware< 1.1.7.61.1.7.6
netgearms60< V1.1.7.128V1.1.7.128
netgearms60_firmware< 1.1.7.1281.1.7.128
netgearms70< V1.0.3.28V1.0.3.28
netgearms70_firmware< 1.0.3.281.0.3.28
netgearms80< V1.1.7.6V1.1.7.6
netgearms80_firmware< 1.1.7.61.1.7.6
netgearrax15<= 1.0.18.144
netgearrax20<= 1.0.18.144
netgearrax200<= 1.0.11.148
netgearrax35v2< V1.0.11.112V1.0.11.112
netgearrax35v2_firmware< 1.0.11.1121.0.11.112
netgearrax38v2< V1.0.11.112V1.0.11.112
netgearrax38v2_firmware< 1.0.11.1121.0.11.112
netgearrax40v2< V1.0.11.112V1.0.11.112
netgearrax40v2_firmware< 1.0.11.1121.0.11.112

CVSS provenance

nvdv3.14.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv4.04.3MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:D/RE:L/U:Amber
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.