CVE-2026-3088
published 2026-06-09CVE-2026-3088: Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
PriorityP430medium4.9CVSS 4.0
AVAACLATNPRNUINVCNVINVAHSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVDRELUAmber
EPSS
0.36%
27.9th percentile
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | rbe970 | >= V6.3.7.10 < V9.10.1.4 | V9.10.1.4 |
| netgear | rbe971 | >= V6.3.7.10 < V9.10.1.4 | V9.10.1.4 |
| netgear | rbr860 | >= V6.3.7.10 < V7.2.7.15 | V7.2.7.15 |
| netgear | rbre950 | < v7.2.7.15 | v7.2.7.15 |
| netgear | rbre960 | >= V6.3.7.10 < V7.2.7.15 | V7.2.7.15 |
| netgear | rbs860 | < V7.2.7.15 | V7.2.7.15 |
| netgear | rbse950 | < v7.2.7.15 | v7.2.7.15 |
| netgear | rbse960 | < V7.2.7.15 | V7.2.7.15 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Netgear RBSE960 prior 7.2.7.15 out-of-bounds write
vuldb·2026-06-09·CVSS 4.9
CVE-2026-3088 [MEDIUM] Netgear RBSE960 prior 7.2.7.15 out-of-bounds write
A vulnerability classified as critical was found in Netgear RBR860, RBRE950, RBRE960, RBRE970, RBRE971, RBS860, RBSE950 and RBSE960. Affected by this issue is some unknown functionality. Executing a manipulation can lead to out-of-bounds write.
The identification of this vulnerability is CVE-2026-3088. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
GHSA
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
ghsa_unreviewed·2026-06-09
CVE-2026-3088 [MEDIUM] CWE-787 Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/rbr860/https://www.netgear.com/support/product/rbre950/https://www.netgear.com/support/product/rbre960/https://www.netgear.com/support/product/rbs860/https://www.netgear.com/support/product/rbse950/https://www.netgear.com/support/product/rbse960/
2026-06-09
Published