CVE-2026-0417

Severity CVSS v4.0:
MEDIUM
Type:
CWE-20 Input Validation
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

Insufficient input validation vulnerability in the listed NETGEAR devices allows<br /> authenticated administrators connected to the local network to tamper with<br /> the router&amp;#39;s integrity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:* 1.1.7.132 (excluding)
cpe:2.3:h:netgear:mr60:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:mr70_firmware:*:*:*:*:*:*:*:* 1.0.3.28 (excluding)
cpe:2.3:h:netgear:mr70:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:mr80_firmware:*:*:*:*:*:*:*:* 1.1.7.14 (excluding)
cpe:2.3:h:netgear:mr80:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:* 1.1.7.132 (excluding)
cpe:2.3:h:netgear:ms60:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ms70_firmware:*:*:*:*:*:*:*:* 1.0.3.28 (excluding)
cpe:2.3:h:netgear:ms70:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ms80_firmware:*:*:*:*:*:*:*:* 1.1.7.14 (excluding)
cpe:2.3:h:netgear:ms80:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6400v2_firmware:*:*:*:*:*:*:*:* 1.0.4.128 (excluding)
cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6700v3_firmware:*:*:*:*:*:*:*:* 1.0.4.128 (excluding)