cbcvebase.
CVE-2026-0418
published 2026-06-09

CVE-2026-0418: Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

PriorityP424medium4.3CVSS 4.0
AVAACLATNPRHUINVCNVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRUVDRELUAmber
EPSS
0.24%
15.6th percentile
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
netgearcbr750< v4.6.14.4v4.6.14.4
netgearex6120<= 1.0.0.72
netgearex6130<= 1.0.0.54
netgearmr60< V1.1.7.128V1.1.7.128
netgearmr70< V1.0.3.28V1.0.3.28
netgearmr80< V1.1.7.6V1.1.7.6
netgearms60< V1.1.7.128V1.1.7.128
netgearms70< V1.0.3.28V1.0.3.28
netgearms80< V1.1.7.6V1.1.7.6
netgearrax15<= 1.0.18.144
netgearrax20<= 1.0.18.144
netgearrax200<= 1.0.11.148
netgearrax35v2< V1.0.11.112V1.0.11.112
netgearrax38v2< V1.0.11.112V1.0.11.112
netgearrax40v2< V1.0.11.112V1.0.11.112
netgearrax42< V1.0.11.112V1.0.11.112
netgearrax43< V1.0.11.112V1.0.11.112
netgearrax45< V1.0.11.112V1.0.11.112
netgearrax48< V1.0.11.112V1.0.11.112
netgearrax50< V1.0.11.112V1.0.11.112
netgearrax50s< V1.0.11.112V1.0.11.112
netgearrax75<= 1.0.11.148
netgearrax80<= 1.0.11.148
netgearraxe450< V1.0.10.86V1.0.10.86
netgearraxe500< V1.0.10.86V1.0.10.86
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.