An insufficient input validation vulnerability in NETGEAR Orbi routers
allows attackers connected to the router's LAN to execute OS command
injections.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 13 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections. | |
| Title | Insufficient input validation in NETGEAR Orbi routers | |
| First Time appeared |
Netgear
Netgear rbe970 Netgear rbe971 Netgear rbr750 Netgear rbr850 Netgear rbr860 Netgear rbre960 Netgear rbs750 Netgear rbs850 Netgear rbs860 Netgear rbse960 |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:h:netgear:rbe970:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe971:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr750:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr850:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr860:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbre960:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs750:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs850:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs860:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbse960:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgear
Netgear rbe970 Netgear rbe971 Netgear rbr750 Netgear rbr850 Netgear rbr860 Netgear rbre960 Netgear rbs750 Netgear rbs850 Netgear rbs860 Netgear rbse960 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NETGEAR
Published:
Updated: 2026-01-13T19:09:31.539Z
Reserved: 2025-12-03T04:16:02.333Z
Link: CVE-2026-0403
Updated: 2026-01-13T19:08:24.923Z
Status : Received
Published: 2026-01-13T16:16:10.150
Modified: 2026-01-13T17:15:59.487
Link: CVE-2026-0403
No data.
OpenCVE Enrichment
No data.