An authentication bypass vulnerability in NETGEAR Orbi devices allows
users connected to the local network to access the router web interface
as an admin.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 13 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin. | |
| Title | Authentication Bypass in NETGEAR Orbi Devices | |
| First Time appeared |
Netgear
Netgear cbr750 Netgear nbr750 Netgear rbe370 Netgear rbe371 Netgear rbe372 Netgear rbe373 Netgear rbe374 Netgear rbe770 Netgear rbe771 Netgear rbe772 Netgear rbe773 Netgear rbe970 Netgear rbe971 Netgear rbr750 Netgear rbr840 Netgear rbr850 Netgear rbr860 Netgear rbre950 Netgear rbre960 Netgear rbs750 Netgear rbs840 Netgear rbs850 Netgear rbs860 Netgear rbse950 Netgear rbse960 |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:h:netgear:cbr750:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:nbr750:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe370:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe371:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe372:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe373:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe374:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe770:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe771:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe772:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe773:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe970:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbe971:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr750:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr840:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr850:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbr860:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbre950:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbre960:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs750:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs840:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs850:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbs860:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbse950:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rbse960:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgear
Netgear cbr750 Netgear nbr750 Netgear rbe370 Netgear rbe371 Netgear rbe372 Netgear rbe373 Netgear rbe374 Netgear rbe770 Netgear rbe771 Netgear rbe772 Netgear rbe773 Netgear rbe970 Netgear rbe971 Netgear rbr750 Netgear rbr840 Netgear rbr850 Netgear rbr860 Netgear rbre950 Netgear rbre960 Netgear rbs750 Netgear rbs840 Netgear rbs850 Netgear rbs860 Netgear rbse950 Netgear rbse960 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NETGEAR
Published:
Updated: 2026-01-13T18:51:16.775Z
Reserved: 2025-12-03T04:16:11.511Z
Link: CVE-2026-0405
Updated: 2026-01-13T18:50:53.486Z
Status : Received
Published: 2026-01-13T16:16:10.513
Modified: 2026-01-13T17:15:59.780
Link: CVE-2026-0405
No data.
OpenCVE Enrichment
No data.