CVE-2026-0408

A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*

History

20 Feb 2026, 19:41

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CPE cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*
First Time Netgear ex6110
Netgear ex5000
Netgear ex2800 Firmware
Netgear ex3110
Netgear ex5000 Firmware
Netgear
Netgear ex3110 Firmware
Netgear ex6110 Firmware
Netgear ex2800
References () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Vendor Advisory, Patch
References () https://www.netgear.com/support/product/ex2800 - () https://www.netgear.com/support/product/ex2800 - Product, Patch
References () https://www.netgear.com/support/product/ex3110 - () https://www.netgear.com/support/product/ex3110 - Product, Patch
References () https://www.netgear.com/support/product/ex5000 - () https://www.netgear.com/support/product/ex5000 - Product, Patch
References () https://www.netgear.com/support/product/ex6110 - () https://www.netgear.com/support/product/ex6110 - Product, Patch

13 Jan 2026, 17:16

Type Values Removed Values Added
References
  • () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory -

13 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:16

Updated : 2026-02-20 19:41


NVD link : CVE-2026-0408

Mitre link : CVE-2026-0408

CVE.ORG link : CVE-2026-0408


JSON object : View

Products Affected

netgear

  • ex6110_firmware
  • ex5000_firmware
  • ex3110
  • ex6110
  • ex2800_firmware
  • ex5000
  • ex3110_firmware
  • ex2800
CWE
CWE-287

Improper Authentication