CVE-2026-0405

EUVD-2026-2237
An authentication bypass vulnerability in NETGEAR Orbi devices allows 
users connected to the local network to access the router web interface 
as an admin.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
Affected Products (NVD)
VendorProductVersion
netgearcbr750_firmware
𝑥
< 4.6.14.8
netgearnbr750_firmware
𝑥
< 4.6.15.14
netgearrbe370_firmware
𝑥
< 12.1.3.11
netgearrbe371_firmware
𝑥
< 12.1.3.11
netgearrbe372_firmware
𝑥
< 12.1.3.11
netgearrbe373_firmware
𝑥
< 12.1.3.11
netgearrbe374_firmware
𝑥
< 12.1.3.11
netgearrbe770_firmware
𝑥
< 10.5.20.7
netgearrbe771_firmware
𝑥
< 10.5.20.7
netgearrbe772_firmware
𝑥
< 10.5.20.7
netgearrbe773_firmware
𝑥
< 10.5.20.7
netgearrbe970_firmware
𝑥
< 9.13.2.1
netgearrbe971_firmware
𝑥
< 9.13.2.1
netgearrbr750_firmware
𝑥
< 7.2.8.2
netgearrbr840_firmware
𝑥
< 7.2.8.2
netgearrbr850_firmware
𝑥
< 7.2.8.2
netgearrbr860_firmware
𝑥
< 7.2.8.2
netgearrbs750_firmware
𝑥
< 7.2.8.2
netgearrbs840_firmware
𝑥
< 7.2.8.2
netgearrbs850_firmware
𝑥
< 7.2.8.2
netgearrbs860_firmware
𝑥
< 7.2.8.2
netgearrbre950_firmware
𝑥
< 7.2.8.2
netgearrbre960_firmware
𝑥
< 7.2.8.2
netgearrbse950_firmware
𝑥
< 7.2.8.2
netgearrbse960_firmware
𝑥
< 7.2.8.2
𝑥
= Vulnerable software versions