An insufficient input validation vulnerability in NETGEAR Orbi routers
allows attackers connected to the router's LAN to execute OS command
injections.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory | Patch Vendor Advisory |
| https://www.netgear.com/support/product/rbe970 | Patch Product |
| https://www.netgear.com/support/product/rbe971 | Patch Product |
| https://www.netgear.com/support/product/rbr750 | Patch Product |
| https://www.netgear.com/support/product/rbr850 | Patch Product |
| https://www.netgear.com/support/product/rbr860 | Patch Product |
| https://www.netgear.com/support/product/rbre960 | Patch Product |
| https://www.netgear.com/support/product/rbs750 | Patch Product |
| https://www.netgear.com/support/product/rbs850 | Patch Product |
| https://www.netgear.com/support/product/rbs860 | Patch Product |
| https://www.netgear.com/support/product/rbse960 | Patch Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
History
20 Feb 2026, 19:38
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:netgear:rbr860:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbse960:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbre960:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbse960_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbre960_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbs860_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbe970_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe971:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe970:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbr860_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbe971_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs860:-:*:*:*:*:*:*:* |
|
| References | () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Patch, Vendor Advisory | |
| References | () https://www.netgear.com/support/product/rbe970 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbe971 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbr750 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbr850 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbr860 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbre960 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs750 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs850 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbs860 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rbse960 - Patch, Product | |
| First Time |
Netgear rbr750
Netgear rbe971 Firmware Netgear rbs850 Netgear rbr860 Netgear Netgear rbse960 Netgear rbe970 Firmware Netgear rbe970 Netgear rbr850 Firmware Netgear rbr850 Netgear rbs850 Firmware Netgear rbs860 Firmware Netgear rbre960 Firmware Netgear rbr860 Firmware Netgear rbs750 Firmware Netgear rbe971 Netgear rbre960 Netgear rbr750 Firmware Netgear rbs750 Netgear rbs860 Netgear rbse960 Firmware |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
13 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 16:16
Updated : 2026-02-20 19:38
NVD link : CVE-2026-0403
Mitre link : CVE-2026-0403
CVE.ORG link : CVE-2026-0403
JSON object : View
Products Affected
netgear
- rbr850
- rbr860
- rbs860
- rbs850_firmware
- rbs750_firmware
- rbs750
- rbe970_firmware
- rbe971
- rbr860_firmware
- rbr850_firmware
- rbe970
- rbs860_firmware
- rbse960
- rbr750
- rbse960_firmware
- rbre960_firmware
- rbr750_firmware
- rbre960
- rbe971_firmware
- rbs850
CWE
CWE-20
Improper Input Validation
