RBRE950
by Netgear
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-0404 | Hig | 0.52 | 8.0 | 0.01 | Jan 13, 2026 | An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default. | ||
| CVE-2026-0405 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin. | ||
| CVE-2026-3088 | Med | 0.32 | — | 0.00 | Jun 9, 2026 | Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests. | ||
| CVE-2026-62655 | Med | 0.00 | — | 0.00 | Jul 14, 2026 | A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable. |
- risk 0.52cvss 8.0epss 0.01
An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.
- risk 0.51cvss 7.8epss 0.00
An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.
- risk 0.32cvss —epss 0.00
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
- risk 0.00cvss —epss 0.00
A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable.