CVE-2026-0405
Detail
Description
An authentication bypass vulnerability in NETGEAR Orbi devices allows
users connected to the local network to access the router web interface
as an admin.
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS 3.x Severity and Vector Strings:
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0 Severity and Vector Strings:
NVD assessment
not yet provided.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
URL
Source(s)
Tag(s)
https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory
Netgear, Inc.
Patch
Vendor Advisory
https://www.netgear.com/support/product/cbr750
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/nbr750
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe370
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe371
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe372
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe373
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe374
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe770
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe771
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe772
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe773
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe970
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbe971
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbr750
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbr840
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbr850
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbr860
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbre950
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbre960
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbs750
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbs840
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbs850
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbs860
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbse950
Netgear, Inc.
Patch
Product
https://www.netgear.com/support/product/rbse960
Netgear, Inc.
Patch
Product
Weakness Enumeration
CWE-ID
CWE Name
Source
NVD-CWE-noinfo
Insufficient Information
NIST  
CWE-287
Improper Authentication
Netgear, Inc.  
Change History
5 change records found show changes
CVE Modified by CISA-ADP
6/17/2026 6:10:45 AM
Action
Type
Old Value
New Value
Added
SSVC
{"timestamp":"2026-01-14T04:57:26.552144Z","id":"CVE-2026-0405","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}
CVE Modified by Netgear, Inc.
6/17/2026 6:10:45 AM
Action
Type
Old Value
New Value
Added
Affected
Record truncated, showing 2048 of 4103 characters.
View Entire Change Record
[{"vendor":"NETGEAR","product":"RBE970","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v9.13.2.1","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBE971","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v9.13.2.1","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"CBR750","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"V4.6.14.8","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"NBR750","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"V4.6.15.14","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBE770","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v10.5.20.7","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBE771","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v10.5.20.7","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBE772","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v10.5.20.7","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBE773","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v10.5.20.7","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBR750","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v7.2.8.2","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBS750","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v7.2.8.2","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBR840","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v7.2.8.2","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBS840","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v7.2.8.2","versionType":"custom","status":"affected"}]},{"vendor":"NETGEAR","product":"RBR850","defaultStatus":"unaffected","versions"
Initial Analysis by NIST
2/12/2026 12:40:40 PM
Action
Type
Old Value
New Value
Added
CVSS V3.1
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Added
CWE
NVD-CWE-noinfo
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:cbr750_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 4.6.14.8
OR
cpe:2.3:h:netgear:cbr750:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:nbr750_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 4.6.15.14
OR
cpe:2.3:h:netgear:nbr750:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe370_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 12.1.3.11
OR
cpe:2.3:h:netgear:rbe370:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe371_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 12.1.3.11
OR
cpe:2.3:h:netgear:rbe371:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe372_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 12.1.3.11
OR
cpe:2.3:h:netgear:rbe372:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe373_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 12.1.3.11
OR
cpe:2.3:h:netgear:rbe373:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe374_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 12.1.3.11
OR
cpe:2.3:h:netgear:rbe374:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe770_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.5.20.7
OR
cpe:2.3:h:netgear:rbe770:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe771_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.5.20.7
OR
cpe:2.3:h:netgear:rbe771:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe772_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.5.20.7
OR
cpe:2.3:h:netgear:rbe772:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe773_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 10.5.20.7
OR
cpe:2.3:h:netgear:rbe773:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe970_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 9.13.2.1
OR
cpe:2.3:h:netgear:rbe970:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbe971_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 9.13.2.1
OR
cpe:2.3:h:netgear:rbe971:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbr840_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbr840:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbr860_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbr860:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbre950_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbre950:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbre960_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbre960:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbs840_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbs840:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbs860_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbs860:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbse950_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbse950:-:*:*:*:*:*:*:*
Added
CPE Configuration
AND
OR
*cpe:2.3:o:netgear:rbse960_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 7.2.8.2
OR
cpe:2.3:h:netgear:rbse960:-:*:*:*:*:*:*:*
Added
Reference Type
Netgear, Inc.: https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory Types: Patch, Vendor Advisory
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/cbr750 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/nbr750 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe370 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe371 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe372 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe373 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe374 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe770 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe771 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe772 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe773 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe970 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbe971 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbr750 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbr840 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbr850 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbr860 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbre950 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbre960 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbs750 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbs840 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbs850 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbs860 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbse950 Types: Patch, Product
Added
Reference Type
Netgear, Inc.: https://www.netgear.com/support/product/rbse960 Types: Patch, Product
CVE Modified by Netgear, Inc.
1/13/2026 12:15:59 PM
Action
Type
Old Value
New Value
Added
Reference
https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory
New CVE Received from Netgear, Inc.
1/13/2026 11:16:10 AM
Action
Type
Old Value
New Value
Added
Description
An authentication bypass vulnerability in NETGEAR Orbi devices allows
users connected to the local network to access the router web interface
as an admin.
Added
CVSS V4.0
AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Added
CWE
CWE-287
Added
Reference
https://www.netgear.com/support/product/cbr750
Added
Reference
https://www.netgear.com/support/product/nbr750
Added
Reference
https://www.netgear.com/support/product/rbe370
Added
Reference
https://www.netgear.com/support/product/rbe371
Added
Reference
https://www.netgear.com/support/product/rbe372
Added
Reference
https://www.netgear.com/support/product/rbe373
Added
Reference
https://www.netgear.com/support/product/rbe374
Added
Reference
https://www.netgear.com/support/product/rbe770
Added
Reference
https://www.netgear.com/support/product/rbe771
Added
Reference
https://www.netgear.com/support/product/rbe772
Added
Reference
https://www.netgear.com/support/product/rbe773
Added
Reference
https://www.netgear.com/support/product/rbe970
Added
Reference
https://www.netgear.com/support/product/rbe971
Added
Reference
https://www.netgear.com/support/product/rbr750
Added
Reference
https://www.netgear.com/support/product/rbr840
Added
Reference
https://www.netgear.com/support/product/rbr850
Added
Reference
https://www.netgear.com/support/product/rbr860
Added
Reference
https://www.netgear.com/support/product/rbre950
Added
Reference
https://www.netgear.com/support/product/rbre960
Added
Reference
https://www.netgear.com/support/product/rbs750
Added
Reference
https://www.netgear.com/support/product/rbs840
Added
Reference
https://www.netgear.com/support/product/rbs850
Added
Reference
https://www.netgear.com/support/product/rbs860
Added
Reference
https://www.netgear.com/support/product/rbse950
Added
Reference
https://www.netgear.com/support/product/rbse960
Quick Info
CVE Dictionary Entry: CVE-2026-0405 NVD
Published Date: 01/13/2026 NVD
Last Modified: 06/17/2026
Source: Netgear, Inc.