CVE-2026-0408

A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*

History

17 Jun 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de salto de ruta en extensores de rango WiFi de NETGEAR permite a un atacante con autenticación LAN acceder a la IP del router y revisar el contenido del archivo webproc generado dinámicamente, que registra el nombre de usuario y la contraseña enviados a la GUI del router.
References () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Vendor Advisory, Patch () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Patch, Vendor Advisory
References () https://www.netgear.com/support/product/ex2800 - Product, Patch () https://www.netgear.com/support/product/ex2800 - Patch, Product
References () https://www.netgear.com/support/product/ex3110 - Product, Patch () https://www.netgear.com/support/product/ex3110 - Patch, Product
References () https://www.netgear.com/support/product/ex5000 - Product, Patch () https://www.netgear.com/support/product/ex5000 - Patch, Product
References () https://www.netgear.com/support/product/ex6110 - Product, Patch () https://www.netgear.com/support/product/ex6110 - Patch, Product

20 Feb 2026, 19:41

Type Values Removed Values Added
First Time Netgear ex6110
Netgear ex5000
Netgear ex2800 Firmware
Netgear ex3110
Netgear ex5000 Firmware
Netgear
Netgear ex3110 Firmware
Netgear ex6110 Firmware
Netgear ex2800
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CPE cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*
References () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Vendor Advisory, Patch
References () https://www.netgear.com/support/product/ex2800 - () https://www.netgear.com/support/product/ex2800 - Product, Patch
References () https://www.netgear.com/support/product/ex3110 - () https://www.netgear.com/support/product/ex3110 - Product, Patch
References () https://www.netgear.com/support/product/ex5000 - () https://www.netgear.com/support/product/ex5000 - Product, Patch
References () https://www.netgear.com/support/product/ex6110 - () https://www.netgear.com/support/product/ex6110 - Product, Patch

13 Jan 2026, 17:16

Type Values Removed Values Added
References
  • () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory -

13 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:16

Updated : 2026-06-17 10:10


NVD link : CVE-2026-0408

Mitre link : CVE-2026-0408

CVE.ORG link : CVE-2026-0408


JSON object : View

Products Affected

netgear

  • ex5000
  • ex2800_firmware
  • ex3110_firmware
  • ex6110
  • ex2800
  • ex6110_firmware
  • ex5000_firmware
  • ex3110
CWE
CWE-287

Improper Authentication