CVE-2026-0407

A

n insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*

History

20 Feb 2026, 19:40

Type Values Removed Values Added
First Time Netgear ex2800
Netgear ex5000 Firmware
Netgear ex6110
Netgear
Netgear ex2800 Firmware
Netgear ex3110 Firmware
Netgear ex6110 Firmware
Netgear ex5000
Netgear ex3110
References () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Vendor Advisory
References () https://www.netgear.com/support/product/ex2800 - () https://www.netgear.com/support/product/ex2800 - Product
References () https://www.netgear.com/support/product/ex3110 - () https://www.netgear.com/support/product/ex3110 - Patch, Product
References () https://www.netgear.com/support/product/ex5000 - () https://www.netgear.com/support/product/ex5000 - Patch, Product
References () https://www.netgear.com/support/product/ex6110 - () https://www.netgear.com/support/product/ex6110 - Patch, Product
CPE cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0

13 Jan 2026, 17:16

Type Values Removed Values Added
References
  • () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory -

13 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:16

Updated : 2026-02-20 19:40


NVD link : CVE-2026-0407

Mitre link : CVE-2026-0407

CVE.ORG link : CVE-2026-0407


JSON object : View

CWE
CWE-287

Improper Authentication