CVE-2026-0403

EUVD-2026-2232
An insufficient input validation vulnerability in NETGEAR Orbi routers 
allows attackers connected to the router's LAN to execute OS command 
injections.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
Affected Products (NVD)
VendorProductVersion
netgearrbe971_firmware
𝑥
< 9.10.0.2
netgearrbe970_firmware
𝑥
< 9.10.0.2
netgearrbr750_firmware
𝑥
< 7.2.8.5
netgearrbr850_firmware
𝑥
< 7.2.8.5
netgearrbr860_firmware
𝑥
< 7.2.8.5
netgearrbs750_firmware
𝑥
< 7.2.8.5
netgearrbs850_firmware
𝑥
< 7.2.8.5
netgearrbs860_firmware
𝑥
< 7.2.8.5
netgearrbre960_firmware
𝑥
< 7.2.8.5
netgearrbse960_firmware
𝑥
< 7.2.8.5
𝑥
= Vulnerable software versions