A
n insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory | Patch Vendor Advisory |
| https://www.netgear.com/support/product/rbr750 | Patch Product |
| https://www.netgear.com/support/product/rbr840 | Patch Product |
| https://www.netgear.com/support/product/rbr850 | Patch Product |
| https://www.netgear.com/support/product/rbr860 | Patch Product |
| https://www.netgear.com/support/product/rbre950 | Patch Product |
| https://www.netgear.com/support/product/rbre960 | Patch Product |
| https://www.netgear.com/support/product/rbs750 | Patch Product |
| https://www.netgear.com/support/product/rbs840 | Patch Product |
| https://www.netgear.com/support/product/rbs850 | Patch Product |
| https://www.netgear.com/support/product/rbs860 | Patch Product |
| https://www.netgear.com/support/product/rbse950 | Patch Product |
| https://www.netgear.com/support/product/rbse960 | Patch Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
History
12 Feb 2026, 17:36
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| First Time |
Netgear rbs750 Firmware
Netgear rbr850 Netgear rbs850 Netgear rbr840 Netgear rbs840 Netgear rbr860 Firmware Netgear Netgear rbr850 Firmware Netgear rbr860 Netgear rbse960 Firmware Netgear rbre950 Netgear rbs850 Firmware Netgear rbr840 Firmware Netgear rbse960 Netgear rbr750 Firmware Netgear rbs860 Netgear rbs860 Firmware Netgear rbre960 Firmware Netgear rbr750 Netgear rbre950 Firmware Netgear rbre960 Netgear rbse950 Netgear rbs840 Firmware Netgear rbse950 Firmware Netgear rbs750 |
|
| CPE | cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbre950_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbse960:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs840_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbre960:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs860_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbse960_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs840:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbre960_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbse950_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbre950:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs860:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr860:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr840:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbse950:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr860_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr840_firmware:*:*:*:*:*:*:*:* |
|
| References | () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Patch, Vendor Advisory | |
| References | () https://www.netgear.com/support/product/rbr750 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbr840 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbr850 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbr860 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbre950 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbre960 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs750 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs840 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs850 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs860 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbse950 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbse960 - Patch, Product | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
13 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 16:16
Updated : 2026-02-12 17:36
NVD link : CVE-2026-0404
Mitre link : CVE-2026-0404
CVE.ORG link : CVE-2026-0404
JSON object : View
Products Affected
CWE