CVE-2026-0419

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:jr6150_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:jr6150:-:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Validación de entrada insuficiente en el NETGEAR JR6150 (Router WiFi AC750 802.11ac de doble banda Gigabit lanzado en 2014) permite a los usuarios conectados a las redes WiFi locales ejecutar comandos del sistema operativo. El NETGEAR JR6150 ha alcanzado la fase de fin de soporte a partir de 2018, y no se planean más actualizaciones de seguridad. NETGEAR recomienda encarecidamente reemplazar estos dispositivos con modelos NETGEAR más nuevos para garantizar un soporte y actualizaciones de seguridad continuos. Esta vulnerabilidad ha sido identificada mediante emulación de firmware en un entorno de investigación controlado y no ha sido verificada en hardware de producción.

18 Jun 2026, 17:09

Type Values Removed Values Added
First Time Netgear jr6150
Netgear
Netgear jr6150 Firmware
CPE cpe:2.3:h:netgear:jr6150:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:jr6150_firmware:-:*:*:*:*:*:*:*
References () https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory - () https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory - Vendor Advisory
References () https://www.netgear.com/support/product/jr6150 - () https://www.netgear.com/support/product/jr6150 - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0

10 Jun 2026, 17:16

Type Values Removed Values Added
References
  • () https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory -

09 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 17:17

Updated : 2026-07-23 08:10


NVD link : CVE-2026-0419

Mitre link : CVE-2026-0419

CVE.ORG link : CVE-2026-0419


JSON object : View

Products Affected

netgear

  • jr6150_firmware
  • jr6150
CWE
CWE-20

Improper Input Validation