Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

NETGEAR strongly recommends that you install the latest firmware as soon as possible. Issue fixed in: ProductFixed VersionCBR750v4.6.14.4EX6120*EOSEX6130*EOSMR60V1.1.7.128MR70V1.0.3.28MR80V1.1.7.6MS60V1.1.7.128MS70V1.0.3.28MS80V1.1.7.6RAX15*EOSRAX20*EOSRAX200*EOSRAX35v2V1.0.11.112RAX38v2V1.0.11.112RAX40v2V1.0.11.112RAX42*V1.0.11.112RAX43*V1.0.11.112RAX45*V1.0.11.112RAX48V1.0.11.112RAX50V1.0.11.112RAX50SV1.0.11.112RAX75*EOSRAX80*EOSRAXE450V1.0.10.86RAXE500V1.0.10.86RBR750V4.6.14.3RBR840*V4.6.14.3RBR850V4.6.14.3RBRE960V6.3.7.5RBS750V4.6.14.3RBS840*V4.6.14.3RBS850V4.6.14.3RBSE960V6.3.7.5RS700 V1.0.7.66 https://www.netgear.com/support/product/rs700/ XR1000v1.0.0.68 * Model has reached its End-of-Support phase and no future security updates are planned. NETGEAR strongly recommends that you retire this device and upgrade to a newer NETGEAR product for continued security support.


Workaround

No workaround given by the vendor.

References
Link Providers
https://www.netgear.com/support/product/cbr750/ cve-icon cve-icon
https://www.netgear.com/support/product/ex6120/ cve-icon cve-icon
https://www.netgear.com/support/product/ex6130/ cve-icon cve-icon
https://www.netgear.com/support/product/mr60/ cve-icon cve-icon
https://www.netgear.com/support/product/mr70/ cve-icon cve-icon
https://www.netgear.com/support/product/mr80/ cve-icon cve-icon
https://www.netgear.com/support/product/ms60/ cve-icon cve-icon
https://www.netgear.com/support/product/ms70/ cve-icon cve-icon
https://www.netgear.com/support/product/ms80/ cve-icon cve-icon
https://www.netgear.com/support/product/rax15/ cve-icon cve-icon
https://www.netgear.com/support/product/rax20/ cve-icon cve-icon
https://www.netgear.com/support/product/rax200/ cve-icon cve-icon
https://www.netgear.com/support/product/rax35v2/ cve-icon cve-icon
https://www.netgear.com/support/product/rax38v2/ cve-icon cve-icon
https://www.netgear.com/support/product/rax40v2/ cve-icon cve-icon
https://www.netgear.com/support/product/rax42/ cve-icon cve-icon
https://www.netgear.com/support/product/rax43/ cve-icon cve-icon
https://www.netgear.com/support/product/rax45/ cve-icon cve-icon
https://www.netgear.com/support/product/rax48/ cve-icon cve-icon
https://www.netgear.com/support/product/rax50/ cve-icon cve-icon
https://www.netgear.com/support/product/rax50s/ cve-icon cve-icon
https://www.netgear.com/support/product/rax75/ cve-icon cve-icon
https://www.netgear.com/support/product/rax80/ cve-icon cve-icon
https://www.netgear.com/support/product/raxe450/ cve-icon cve-icon
https://www.netgear.com/support/product/raxe500/ cve-icon cve-icon
https://www.netgear.com/support/product/rbr750/ cve-icon cve-icon
https://www.netgear.com/support/product/rbr840/ cve-icon cve-icon
https://www.netgear.com/support/product/rbr850/ cve-icon cve-icon
https://www.netgear.com/support/product/rbre960/ cve-icon cve-icon
https://www.netgear.com/support/product/rbs750/ cve-icon cve-icon
https://www.netgear.com/support/product/rbs840/ cve-icon cve-icon
https://www.netgear.com/support/product/rbs850/ cve-icon cve-icon
https://www.netgear.com/support/product/rbse960/ cve-icon cve-icon
https://www.netgear.com/support/product/rs700/ cve-icon cve-icon
https://www.netgear.com/support/product/xr1000/ cve-icon cve-icon
History

Tue, 09 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Description Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
Title Certain NETGEAR devices allow administrators to tamper with system
Weaknesses CWE-15
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/R:U/V:D/RE:L/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-06-09T17:09:21.456Z

Reserved: 2025-12-03T04:16:25.029Z

Link: CVE-2026-0418

cve-icon Vulnrichment

Updated: 2026-06-09T17:08:25.369Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:16:59.687

Modified: 2026-06-09T19:38:32.463

Link: CVE-2026-0418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T17:30:10Z

Weaknesses