CVE-2026-0404

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:rbr840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr840:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:rbr860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr860:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netgear:rbs840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs840:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netgear:rbs860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs860:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netgear:rbre950_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbre950:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netgear:rbre960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbre960:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:netgear:rbse950_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbse950:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:netgear:rbse960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbse960:-:*:*:*:*:*:*:*

History

12 Feb 2026, 17:36

Type Values Removed Values Added
First Time Netgear rbre950
Netgear rbr750
Netgear rbr840 Firmware
Netgear rbs840 Firmware
Netgear rbs850
Netgear rbr860
Netgear
Netgear rbse960
Netgear rbs840
Netgear rbr850 Firmware
Netgear rbre950 Firmware
Netgear rbr850
Netgear rbr840
Netgear rbs850 Firmware
Netgear rbs860 Firmware
Netgear rbre960 Firmware
Netgear rbr860 Firmware
Netgear rbse950 Firmware
Netgear rbse950
Netgear rbs750 Firmware
Netgear rbre960
Netgear rbr750 Firmware
Netgear rbs750
Netgear rbs860
Netgear rbse960 Firmware
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CPE cpe:2.3:h:netgear:rbr860:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbse960:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr840:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbre960:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbse960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbs840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbre950:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbre960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbse950:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbre950_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbs860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbr840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs840:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbr860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbse950_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs860:-:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Patch, Vendor Advisory
References () https://www.netgear.com/support/product/rbr750 - () https://www.netgear.com/support/product/rbr750 - Patch, Product
References () https://www.netgear.com/support/product/rbr840 - () https://www.netgear.com/support/product/rbr840 - Patch, Product
References () https://www.netgear.com/support/product/rbr850 - () https://www.netgear.com/support/product/rbr850 - Patch, Product
References () https://www.netgear.com/support/product/rbr860 - () https://www.netgear.com/support/product/rbr860 - Patch, Product
References () https://www.netgear.com/support/product/rbre950 - () https://www.netgear.com/support/product/rbre950 - Patch, Product
References () https://www.netgear.com/support/product/rbre960 - () https://www.netgear.com/support/product/rbre960 - Patch, Product
References () https://www.netgear.com/support/product/rbs750 - () https://www.netgear.com/support/product/rbs750 - Patch, Product
References () https://www.netgear.com/support/product/rbs840 - () https://www.netgear.com/support/product/rbs840 - Patch, Product
References () https://www.netgear.com/support/product/rbs850 - () https://www.netgear.com/support/product/rbs850 - Patch, Product
References () https://www.netgear.com/support/product/rbs860 - () https://www.netgear.com/support/product/rbs860 - Patch, Product
References () https://www.netgear.com/support/product/rbse950 - () https://www.netgear.com/support/product/rbse950 - Patch, Product
References () https://www.netgear.com/support/product/rbse960 - () https://www.netgear.com/support/product/rbse960 - Patch, Product

13 Jan 2026, 17:15

Type Values Removed Values Added
References
  • () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory -

13 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:16

Updated : 2026-02-12 17:36


NVD link : CVE-2026-0404

Mitre link : CVE-2026-0404

CVE.ORG link : CVE-2026-0404


JSON object : View

Products Affected

netgear

  • rbr850
  • rbr860
  • rbs860
  • rbs850_firmware
  • rbs750_firmware
  • rbs750
  • rbr860_firmware
  • rbs840
  • rbr850_firmware
  • rbs860_firmware
  • rbse950
  • rbse960
  • rbre950_firmware
  • rbr750
  • rbse960_firmware
  • rbr840
  • rbre960_firmware
  • rbs840_firmware
  • rbse950_firmware
  • rbre950
  • rbr750_firmware
  • rbr840_firmware
  • rbre960
  • rbs850
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo