6.1
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:N/R:U/V:D/RE:M/U:Amber
Description
An insufficient input validation vulnerability in the NETGEAR XR1000v2
allows attackers connected to the router's LAN to execute OS command
injections.
allows attackers connected to the router's LAN to execute OS command
injections.
Basic Information
ID
CVE-2026-0406
Source
NETGEAR
Published
Jan 13, 2026 at 16:00
Modified
Jan 13, 2026 at 16:21
Affected Product
Vendor
NETGEAR
Product
XR1000v2
Affected Versions
NETGEAR XR1000v2 0