1.1
/ 10
LOW
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
Description
An insufficient input validation vulnerability in NETGEAR Orbi routers
allows attackers connected to the router's LAN to execute OS command
injections.
allows attackers connected to the router's LAN to execute OS command
injections.
Basic Information
ID
CVE-2026-0403
Source
NETGEAR
Published
Jan 13, 2026 at 16:00
Modified
Jan 13, 2026 at 16:20
Affected Product
Vendor
NETGEAR
Product
RBR750
Affected Versions
NETGEAR RBR750 0
NETGEAR RBS750 0
NETGEAR RBRE960 0
NETGEAR RBSE960 0
NETGEAR RBR850 0
NETGEAR RBS850 0
NETGEAR RBE971 0
NETGEAR RBE970 0
NETGEAR RBR860 0
NETGEAR RBS860 0
NETGEAR RBS750 0
NETGEAR RBRE960 0
NETGEAR RBSE960 0
NETGEAR RBR850 0
NETGEAR RBS850 0
NETGEAR RBE971 0
NETGEAR RBE970 0
NETGEAR RBR860 0
NETGEAR RBS860 0
CWE Classification
References
- www.netgear.com /support/product/rbr750
- www.netgear.com /support/product/rbs750
- www.netgear.com /support/product/rbre960
- www.netgear.com /support/product/rbse960
- www.netgear.com /support/product/rbr850
- www.netgear.com /support/product/rbs850
- www.netgear.com /support/product/rbe971
- www.netgear.com /support/product/rbe970
- www.netgear.com /support/product/rbr860
- www.netgear.com /support/product/rbs860
- kb.netgear.com /000070442/January-2026-NETGEAR-Security-Advisory