CVE-2026-0405

HIGH WAF: Low
CVSS 7.8 Published: 2026-01-13
CWE-287

An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
netgearcbr750_firmwareup to 4.6.14.8
netgearnbr750_firmwareup to 4.6.15.14
netgearrbe370_firmwareup to 12.1.3.11
netgearrbe371_firmwareup to 12.1.3.11
netgearrbe372_firmwareup to 12.1.3.11
netgearrbe373_firmwareup to 12.1.3.11
netgearrbe374_firmwareup to 12.1.3.11
netgearrbe770_firmwareup to 10.5.20.7
netgearrbe771_firmwareup to 10.5.20.7
netgearrbe772_firmwareup to 10.5.20.7

References

Back to CVE Database