VYPR

RBSE960

by Netgear

CVEs (3)

  • CVE-2026-0404HigJan 13, 2026
    risk 0.52cvss 8.0epss 0.01

    An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

  • CVE-2026-0403HigJan 13, 2026
    risk 0.52cvss 8.0epss 0.00

    An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

  • CVE-2026-0405HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.