A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory | Vendor Advisory |
| https://www.netgear.com/support/product/rbe372/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
23 Jul 2026, 08:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
18 Jun 2026, 18:37
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:netgear:rbe370_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbe371_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe370:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe371:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbe374_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rbe372_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe374:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe372:-:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.4 |
| First Time |
Netgear rbe374
Netgear rbe371 Netgear rbe370 Firmware Netgear rbe370 Netgear rbe374 Firmware Netgear Netgear rbe372 Firmware Netgear rbe372 Netgear rbe371 Firmware |
|
| References | () https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory - Vendor Advisory | |
| References | () https://www.netgear.com/support/product/rbe372/ - Product |
10 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 17:16
Updated : 2026-07-23 08:10
NVD link : CVE-2026-0409
Mitre link : CVE-2026-0409
CVE.ORG link : CVE-2026-0409
JSON object : View
Products Affected
netgear
- rbe374
- rbe370_firmware
- rbe370
- rbe374_firmware
- rbe372
- rbe371
- rbe372_firmware
- rbe371_firmware
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
