CVE-2026-3088
published 2026-06-09CVE-2026-3088: Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
PriorityP431medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.36%
28.8th percentile
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | rbe970 | >= V6.3.7.10 < V9.10.1.4 | V9.10.1.4 |
| netgear | rbe970_firmware | < 9.10.1.4 | 9.10.1.4 |
| netgear | rbe971 | >= V6.3.7.10 < V9.10.1.4 | V9.10.1.4 |
| netgear | rbe971_firmware | < 9.10.1.4 | 9.10.1.4 |
| netgear | rbr860 | >= V6.3.7.10 < V7.2.7.15 | V7.2.7.15 |
| netgear | rbr860_firmware | < 7.2.7.15 | 7.2.7.15 |
| netgear | rbre950 | < v7.2.7.15 | v7.2.7.15 |
| netgear | rbre950_firmware | < 7.2.7.15 | 7.2.7.15 |
| netgear | rbre960 | >= V6.3.7.10 < V7.2.7.15 | V7.2.7.15 |
| netgear | rbre960_firmware | < 7.2.7.15 | 7.2.7.15 |
| netgear | rbs860 | < V7.2.7.15 | V7.2.7.15 |
| netgear | rbs860_firmware | < 7.2.7.15 | 7.2.7.15 |
| netgear | rbse950 | < v7.2.7.15 | v7.2.7.15 |
| netgear | rbse950_firmware | < 7.2.7.15 | 7.2.7.15 |
| netgear | rbse960 | < V7.2.7.15 | V7.2.7.15 |
| netgear | rbse960_firmware | < 7.2.7.15 | 7.2.7.15 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.04.9MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Netgear RBSE960 prior 7.2.7.15 out-of-bounds write
vuldb·2026-06-09·CVSS 4.9
CVE-2026-3088 [MEDIUM] Netgear RBSE960 prior 7.2.7.15 out-of-bounds write
A vulnerability classified as critical was found in Netgear RBR860, RBRE950, RBRE960, RBRE970, RBRE971, RBS860, RBSE950 and RBSE960. Affected by this issue is some unknown functionality. Executing a manipulation can lead to out-of-bounds write.
The identification of this vulnerability is CVE-2026-3088. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
GHSA
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
ghsa_unreviewed·2026-06-09
CVE-2026-3088 [MEDIUM] CWE-787 Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
No detection rules found.
No public exploits indexed.
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/rbr860/https://www.netgear.com/support/product/rbre950/https://www.netgear.com/support/product/rbre960/https://www.netgear.com/support/product/rbs860/https://www.netgear.com/support/product/rbse950/https://www.netgear.com/support/product/rbse960/
2026-06-09
Published