cbcvebase.

Netgear Rbr860 Firmware vulnerabilities

6 known vulnerabilities affecting netgear/rbr860_firmware.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2026-0404P3HIGHCVSS 8.0fixed in 7.2.8.52026-01-13
CVE-2026-0404 [HIGH] CWE-20 CVE-2026-0404: An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.
nvd
CVE-2026-0405P3HIGHCVSS 7.8fixed in 7.2.8.22026-01-13
CVE-2026-0405 [HIGH] CWE-287 CVE-2026-0405: An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.
nvd
CVE-2026-0403P3HIGHCVSS 8.0fixed in 7.2.8.52026-01-13
CVE-2026-0403 [HIGH] CWE-20 CVE-2026-0403: An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected t An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.
nvd
CVE-2026-3088P4MEDIUMCVSS 6.5fixed in 7.2.7.152026-06-09
CVE-2026-3088 [MEDIUM] CWE-787 CVE-2026-3088: Unauthenticated users on the local network can cause the router to become unavailable by sending spe Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
nvd
CVE-2026-0413P4MEDIUMCVSS 4.5fixed in 7.2.8.52026-06-09
CVE-2026-0413 [MEDIUM] CWE-121 CVE-2026-0413: A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models al A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
nvd
CVE-2026-0415P4MEDIUMCVSS 4.5fixed in 7.2.8.52026-06-09
CVE-2026-0415 [MEDIUM] CWE-20 CVE-2026-0415: Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
nvd
Netgear Rbr860 Firmware vulnerabilities | cvebase