A path traversal vulnerability in NETGEAR WiFi range extenders allows
an attacker with LAN authentication to access the router's IP and
review the contents of the dynamically generated webproc file, which
records the username and password submitted to the router GUI.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory | Vendor Advisory Patch |
| https://www.netgear.com/support/product/ex2800 | Product Patch |
| https://www.netgear.com/support/product/ex3110 | Product Patch |
| https://www.netgear.com/support/product/ex5000 | Product Patch |
| https://www.netgear.com/support/product/ex6110 | Product Patch |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
20 Feb 2026, 19:41
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
| CPE | cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:* |
|
| First Time |
Netgear ex6110
Netgear ex5000 Netgear ex2800 Firmware Netgear ex3110 Netgear ex5000 Firmware Netgear Netgear ex3110 Firmware Netgear ex6110 Firmware Netgear ex2800 |
|
| References | () https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory - Vendor Advisory, Patch | |
| References | () https://www.netgear.com/support/product/ex2800 - Product, Patch | |
| References | () https://www.netgear.com/support/product/ex3110 - Product, Patch | |
| References | () https://www.netgear.com/support/product/ex5000 - Product, Patch | |
| References | () https://www.netgear.com/support/product/ex6110 - Product, Patch |
13 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 16:16
Updated : 2026-02-20 19:41
NVD link : CVE-2026-0408
Mitre link : CVE-2026-0408
CVE.ORG link : CVE-2026-0408
JSON object : View
Products Affected
netgear
- ex6110_firmware
- ex5000_firmware
- ex3110
- ex6110
- ex2800_firmware
- ex5000
- ex3110_firmware
- ex2800
CWE
CWE-287
Improper Authentication
