CVE-2026-0404HIGH 8.0EPSS p60.3%
CVE-2026-0404CVE-2026-0404
Description
An insufficient input validation vulnerability in NETGEAR Orbi devices'
DHCPv6 functionality allows network adjacent attackers authenticated
over WiFi or on LAN to execute OS command injections on the router.
DHCPv6 is not enabled by default.
Scoring
| CVSS 3.1 | 8.0 (HIGH) |
| Vector | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.06% probability of exploitation · percentile 60.3% · 2026-06-19T12:03:05Z |
| Published | 2026-01-13 |
| Last modified | 2026-02-12 |
Underlying weaknesses· 1
References
- https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory
- https://www.netgear.com/support/product/rbr750
- https://www.netgear.com/support/product/rbr840
- https://www.netgear.com/support/product/rbr850
- https://www.netgear.com/support/product/rbr860
- https://www.netgear.com/support/product/rbre950
- https://www.netgear.com/support/product/rbre960
- https://www.netgear.com/support/product/rbs750
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Input Validationcwe-20 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.