Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system.
Advisories

No advisories yet.

Fixes

Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionCBR750 Orbi WiFi 6 DOCSIS 3.1 Mesh WiFi Cable Modem Router v4.6.14.4 https://www.netgear.com/support/product/cbr750/ EX6120 (EoS) AC1200 Dual Band WiFi Range ExtenderEOSEX6130 (EoS) AC1200 WiFi Range ExtenderEOSMR60 Nighthawk Mesh WiFi 6 Router V1.1.7.128 https://www.netgear.com/support/product/mr60/ MR70 Nighthawk Mesh WiFi 6 Router V1.0.3.28 https://www.netgear.com/support/product/mr70/ MR80 Nighthawk Tri-band Mesh WiFi 6 Router V1.1.7.6 https://www.netgear.com/support/product/mr80/ MS60 Nighthawk Mesh WiFi 6 Add-on Satellite V1.1.7.128 https://www.netgear.com/support/product/ms60/ MS70 Nighthawk Mesh WiFi 6 Add-on Satellite V1.0.3.28 https://www.netgear.com/support/product/ms70/ MS80 Nighthawk Tri-band Mesh WiFi 6 Add-on Satellite V1.1.7.6 https://www.netgear.com/support/product/ms80/ RAX15(EoS) 4-Stream AX1800 WiFi 6 RouterEOSRAX20 (EoS) 4-Stream AX1800 WiFi 6 RouterEOSRAX200 (EoS) Nighthawk Tri-Band AX12 12-Stream WiFi RouterEOSRAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router V1.0.11.112 https://www.netgear.com/support/product/rax35v2/ RAX38v2 Nighthawk AX4 4-Stream AX3000 WiFi Router V1.0.11.112 https://www.netgear.com/support/product/rax38v2/ RAX40v2 Nighthawk AX4 4-Stream WiFi Router V1.0.11.112 https://www.netgear.com/support/product/rax40v2/ RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.0.11.112 https://www.netgear.com/support/product/rax42/ RAX43 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.0.11.112 https://www.netgear.com/support/product/rax43/ RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router V1.0.11.112 https://www.netgear.com/support/product/rax45/ RAX48 Nighthawk AX6 6-Stream AX5200 WiFi 6 Router V1.0.11.112 https://www.netgear.com/support/product/rax48/ RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.11.112 https://www.netgear.com/support/product/rax50/ RAX50S Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.11.112 https://www.netgear.com/support/product/rax50s/ RAX75 (EoS) Nighthawk AX8 8-Stream AX5700 WiFi 6 RouterEOSRAX80 (EoS) Nighthawk AX8 8-Stream WiFi RouterEOSRAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Router V1.0.10.86 https://www.netgear.com/support/product/raxe450/ RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.0.10.86 https://www.netgear.com/support/product/raxe500/ RBR750 Orbi WiFi 6 Router AX4200 V4.6.14.3 https://www.netgear.com/support/product/rbr750/ RBR840 (EoS) Orbi WiFi 6 System AX5700 V4.6.14.3 https://www.netgear.com/support/product/rbr840/ RBR850 Orbi WiFi 6 Router AX6000 V4.6.14.3 https://www.netgear.com/support/product/rbr850/ RBRE960 Orbi Quad-band Mesh WiFi 6E Router V6.3.7.5 https://www.netgear.com/support/product/rbre960/ RBS750 Orbi WiFi 6 Add-on Satellite AX4200 V4.6.14.3 https://www.netgear.com/support/product/rbs750/ RBS840 (EoS) Orbi WiFi 6 Add-on Satellite AX5700 V4.6.14.3 https://www.netgear.com/support/product/rbs840/ RBS850 Orbi WiFi 6 Satellite AX6000 V4.6.14.3 https://www.netgear.com/support/product/rbs850/ RBSE960 Orbi Quad-band Mesh WiFi 6E Add-on Satellite V6.3.7.5 https://www.netgear.com/support/product/rbse960/ RS700 Nighthawk BE19000 WiFi 7 Tri-Band Router V1.0.7.66 https://www.netgear.com/support/product/rs700/ XR1000 Nighthawk WiFi 6 Pro Gaming Router v1.0.0.68 https://www.netgear.com/support/product/xr1000/ Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


Workaround

No workaround given by the vendor.

References
Link Providers
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory cve-icon cve-icon
https://www.netgear.com/support/product/cbr750/ cve-icon cve-icon
https://www.netgear.com/support/product/ex6120/ cve-icon cve-icon
https://www.netgear.com/support/product/ex6130/ cve-icon cve-icon
https://www.netgear.com/support/product/mr60/ cve-icon cve-icon
https://www.netgear.com/support/product/mr70/ cve-icon cve-icon
https://www.netgear.com/support/product/mr80/ cve-icon cve-icon
https://www.netgear.com/support/product/ms60/ cve-icon cve-icon
https://www.netgear.com/support/product/ms70/ cve-icon cve-icon
https://www.netgear.com/support/product/ms80/ cve-icon cve-icon
https://www.netgear.com/support/product/rax15/ cve-icon cve-icon
https://www.netgear.com/support/product/rax20/ cve-icon cve-icon
https://www.netgear.com/support/product/rax200/ cve-icon cve-icon
https://www.netgear.com/support/product/rax35v2/ cve-icon cve-icon
https://www.netgear.com/support/product/rax38v2/ cve-icon cve-icon
https://www.netgear.com/support/product/rax40v2/ cve-icon cve-icon
https://www.netgear.com/support/product/rax42/ cve-icon cve-icon
https://www.netgear.com/support/product/rax43/ cve-icon cve-icon
https://www.netgear.com/support/product/rax45/ cve-icon cve-icon
https://www.netgear.com/support/product/rax48/ cve-icon cve-icon
https://www.netgear.com/support/product/rax50/ cve-icon cve-icon
https://www.netgear.com/support/product/rax50s/ cve-icon cve-icon
https://www.netgear.com/support/product/rax75/ cve-icon cve-icon
https://www.netgear.com/support/product/rax80/ cve-icon cve-icon
https://www.netgear.com/support/product/raxe450/ cve-icon cve-icon
https://www.netgear.com/support/product/raxe500/ cve-icon cve-icon
https://www.netgear.com/support/product/rbr750/ cve-icon cve-icon
https://www.netgear.com/support/product/rbr840/ cve-icon cve-icon
https://www.netgear.com/support/product/rbr850/ cve-icon cve-icon
https://www.netgear.com/support/product/rbre960/ cve-icon cve-icon
https://www.netgear.com/support/product/rbs750/ cve-icon cve-icon
https://www.netgear.com/support/product/rbs840/ cve-icon cve-icon
https://www.netgear.com/support/product/rbs850/ cve-icon cve-icon
https://www.netgear.com/support/product/rbse960/ cve-icon cve-icon
https://www.netgear.com/support/product/rs700/ cve-icon cve-icon
https://www.netgear.com/support/product/xr1000/ cve-icon cve-icon
History

Wed, 10 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
References

Tue, 09 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear cbr750
Netgear ex6120
Netgear ex6130
Netgear mr60
Netgear mr70
Netgear mr80
Netgear ms60
Netgear ms70
Netgear ms80
Netgear rax15
Netgear rax20
Netgear rax200
Netgear rax35v2
Netgear rax38v2
Netgear rax40v2
Netgear rax42
Netgear rax43
Netgear rax45
Netgear rax48
Netgear rax50
Netgear rax50s
Netgear rax75
Netgear rax80
Netgear raxe450
Netgear raxe500
Netgear rbr750
Netgear rbr840
Netgear rbr850
Netgear rbre960
Netgear rbs750
Netgear rbs840
Netgear rbs850
Netgear rbse960
Netgear rs700
Netgear xr1000
Vendors & Products Netgear
Netgear cbr750
Netgear ex6120
Netgear ex6130
Netgear mr60
Netgear mr70
Netgear mr80
Netgear ms60
Netgear ms70
Netgear ms80
Netgear rax15
Netgear rax20
Netgear rax200
Netgear rax35v2
Netgear rax38v2
Netgear rax40v2
Netgear rax42
Netgear rax43
Netgear rax45
Netgear rax48
Netgear rax50
Netgear rax50s
Netgear rax75
Netgear rax80
Netgear raxe450
Netgear raxe500
Netgear rbr750
Netgear rbr840
Netgear rbr850
Netgear rbre960
Netgear rbs750
Netgear rbs840
Netgear rbs850
Netgear rbse960
Netgear rs700
Netgear xr1000

Tue, 09 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Description Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
Title Certain NETGEAR devices allow administrators to tamper with system
Weaknesses CWE-15
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/R:U/V:D/RE:L/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-06-10T15:56:54.459Z

Reserved: 2025-12-03T04:16:25.029Z

Link: CVE-2026-0418

cve-icon Vulnrichment

Updated: 2026-06-09T17:08:25.369Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:16:59.687

Modified: 2026-06-10T17:16:31.473

Link: CVE-2026-0418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T20:20:21Z

Weaknesses