CVE-2026-0408

A

path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*

History

20 Feb 2026, 19:41

Type Values Removed Values Added
First Time Netgear ex2800
Netgear ex5000 Firmware
Netgear ex6110
Netgear
Netgear ex2800 Firmware
Netgear ex3110 Firmware
Netgear ex6110 Firmware
Netgear ex5000
Netgear ex3110
CPE cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
References () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Vendor Advisory, Patch
References () https://www.netgear.com/support/product/ex2800 - () https://www.netgear.com/support/product/ex2800 - Product, Patch
References () https://www.netgear.com/support/product/ex3110 - () https://www.netgear.com/support/product/ex3110 - Product, Patch
References () https://www.netgear.com/support/product/ex5000 - () https://www.netgear.com/support/product/ex5000 - Product, Patch
References () https://www.netgear.com/support/product/ex6110 - () https://www.netgear.com/support/product/ex6110 - Product, Patch

13 Jan 2026, 17:16

Type Values Removed Values Added
References
  • () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory -

13 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:16

Updated : 2026-02-20 19:41


NVD link : CVE-2026-0408

Mitre link : CVE-2026-0408

CVE.ORG link : CVE-2026-0408


JSON object : View

CWE
CWE-287

Improper Authentication