VYPR

RBR860

by Netgear

CVEs (5)

  • CVE-2026-0404HigJan 13, 2026
    risk 0.52cvss 8.0epss 0.01

    An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

  • CVE-2026-0403HigJan 13, 2026
    risk 0.52cvss 8.0epss 0.00

    An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

  • CVE-2026-0405HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

  • CVE-2026-3088MedJun 9, 2026
    risk 0.32cvss epss 0.00

    Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.

  • CVE-2026-62655MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable.