CVE-2026-0407

An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*

History

20 Feb 2026, 19:40

Type Values Removed Values Added
References () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Vendor Advisory
References () https://www.netgear.com/support/product/ex2800 - () https://www.netgear.com/support/product/ex2800 - Product
References () https://www.netgear.com/support/product/ex3110 - () https://www.netgear.com/support/product/ex3110 - Patch, Product
References () https://www.netgear.com/support/product/ex5000 - () https://www.netgear.com/support/product/ex5000 - Patch, Product
References () https://www.netgear.com/support/product/ex6110 - () https://www.netgear.com/support/product/ex6110 - Patch, Product
First Time Netgear ex6110
Netgear ex5000
Netgear ex2800 Firmware
Netgear ex3110
Netgear ex5000 Firmware
Netgear
Netgear ex3110 Firmware
Netgear ex6110 Firmware
Netgear ex2800
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CPE cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*

13 Jan 2026, 17:16

Type Values Removed Values Added
References
  • () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory -

13 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:16

Updated : 2026-02-20 19:40


NVD link : CVE-2026-0407

Mitre link : CVE-2026-0407

CVE.ORG link : CVE-2026-0407


JSON object : View

Products Affected

netgear

  • ex6110_firmware
  • ex5000_firmware
  • ex3110
  • ex6110
  • ex2800_firmware
  • ex5000
  • ex3110_firmware
  • ex2800
CWE
CWE-287

Improper Authentication