CVE-2026-0408HIGH 8.0EPSS p13.3%
CVE-2026-0408CVE-2026-0408
Description
A path traversal vulnerability in NETGEAR WiFi range extenders allows
an attacker with LAN authentication to access the router's IP and
review the contents of the dynamically generated webproc file, which
records the username and password submitted to the router GUI.
Scoring
| CVSS 3.1 | 8.0 (HIGH) |
| Vector | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.23% probability of exploitation · percentile 13.3% · 2026-06-19T12:03:05Z |
| Published | 2026-01-13 |
| Last modified | 2026-02-20 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Authenticationcwe-287 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.