A
n insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory | Patch Vendor Advisory |
| https://www.netgear.com/support/product/rbe970 | Patch Product |
| https://www.netgear.com/support/product/rbe971 | Patch Product |
| https://www.netgear.com/support/product/rbr750 | Patch Product |
| https://www.netgear.com/support/product/rbr850 | Patch Product |
| https://www.netgear.com/support/product/rbr860 | Patch Product |
| https://www.netgear.com/support/product/rbre960 | Patch Product |
| https://www.netgear.com/support/product/rbs750 | Patch Product |
| https://www.netgear.com/support/product/rbs850 | Patch Product |
| https://www.netgear.com/support/product/rbs860 | Patch Product |
| https://www.netgear.com/support/product/rbse960 | Patch Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
History
20 Feb 2026, 19:38
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Netgear rbs750 Firmware
Netgear rbr850 Netgear rbe970 Firmware Netgear rbs850 Netgear rbr860 Firmware Netgear Netgear rbr850 Firmware Netgear rbr860 Netgear rbse960 Firmware Netgear rbe971 Firmware Netgear rbe971 Netgear rbs850 Firmware Netgear rbse960 Netgear rbr750 Firmware Netgear rbs860 Netgear rbs860 Firmware Netgear rbre960 Firmware Netgear rbr750 Netgear rbe970 Netgear rbre960 Netgear rbs750 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
| References | () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Patch, Vendor Advisory | |
| References | () https://www.netgear.com/support/product/rbe970 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbe971 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbr750 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbr850 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbr860 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbre960 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs750 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs850 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs860 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbse960 - Patch, Product | |
| CPE | cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe970:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbe970_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbse960:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbre960:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbe971_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs860_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbse960_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbre960_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs860:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr860:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr860_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe971:-:*:*:*:*:*:*:* |
13 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 16:16
Updated : 2026-02-20 19:38
NVD link : CVE-2026-0403
Mitre link : CVE-2026-0403
CVE.ORG link : CVE-2026-0403
JSON object : View
Products Affected
CWE
CWE-20
Improper Input Validation