← Vulnerability feed

Vulnerability record · CVE-2026-0411 · published 9 June 2026

CVE-2026-0411: Netgear rbe970 firmware information exposure vulnerability

Netgear · Rbe970 Firmware

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this issue.

4.2 CVSS 4.0 Medium EPSS 0.28% · top 81.8% CWE-200 · Information exposure
4.2CVSS 4.0 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
6References
23 Jul 2026Last modified by NVD

Description

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this issue.

CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-0411 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-45619Netgear ex6250 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects EX6200v2 before 1.0.1.86, EX6250 before 1.0.0.…EPSS 2.5%8.8CVE-2023-41183Netgear rbr760 firmware missing authentication for critical function vulnerabilityNETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affec…EPSS 14%8.8CVE-2021-45520Netgear rbk352 firmware hard-coded credentials vulnerabilityCertain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.EPSS 0.41%7.5CVE-2021-45648Netgear ex6100v2 firmware information exposure vulnerabilityCertain NETGEAR devices are affected by disclosure of sensitive information. This affects EX6100v2 before 1.0.1.106, EX6150v2 before 1.0.1.106, EX625…EPSS 0.78%7.5CVE-2021-45652Netgear rbk352 firmware information exposure vulnerabilityCertain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 …EPSS 1.0%7.5CVE-2021-45653Netgear rbk352 firmware information exposure vulnerabilityCertain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 …EPSS 1.4%6.5CVE-2021-45521Netgear rbk352 firmware hard-coded credentials vulnerabilityCertain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.EPSS 0.36%6.1CVE-2026-0405Netgear cbr750 firmware improper authentication vulnerabilityAn authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an a…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2026-0411), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.