CVE-2026-0407

EUVD-2026-2231
An insufficient authentication vulnerability in NETGEAR WiFi range 
extenders allows a network adjacent attacker with WiFi authentication or
 a physical Ethernet port connection to bypass the authentication 
process and access the admin panel.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
netgearex5000_firmware
𝑥
< 1.0.1.82
netgearex3110_firmware
𝑥
< 1.0.1.82
netgearex6110_firmware
𝑥
< 1.0.1.82
netgearex2800_firmware
𝑥
< 1.0.1.82
𝑥
= Vulnerable software versions