A
path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory | Vendor Advisory Patch |
| https://www.netgear.com/support/product/ex2800 | Product Patch |
| https://www.netgear.com/support/product/ex3110 | Product Patch |
| https://www.netgear.com/support/product/ex5000 | Product Patch |
| https://www.netgear.com/support/product/ex6110 | Product Patch |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
20 Feb 2026, 19:41
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Netgear ex2800
Netgear ex5000 Firmware Netgear ex6110 Netgear Netgear ex2800 Firmware Netgear ex3110 Firmware Netgear ex6110 Firmware Netgear ex5000 Netgear ex3110 |
|
| CPE | cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
| References | () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Vendor Advisory, Patch | |
| References | () https://www.netgear.com/support/product/ex2800 - Product, Patch | |
| References | () https://www.netgear.com/support/product/ex3110 - Product, Patch | |
| References | () https://www.netgear.com/support/product/ex5000 - Product, Patch | |
| References | () https://www.netgear.com/support/product/ex6110 - Product, Patch |
13 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 16:16
Updated : 2026-02-20 19:41
NVD link : CVE-2026-0408
Mitre link : CVE-2026-0408
CVE.ORG link : CVE-2026-0408
JSON object : View
Products Affected
CWE
CWE-287
Improper Authentication