CVE-2026-0405
Severity CVSS v4.0:
MEDIUM
Type:
CWE-287
Authentication Issues
Publication date:
13/01/2026
Last modified:
12/02/2026
Description
An authentication bypass vulnerability in NETGEAR Orbi devices allows <br />
users connected to the local network to access the router web interface <br />
as an admin.
Impact
Base Score 4.0
6.10
Severity 4.0
MEDIUM
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:netgear:cbr750_firmware:*:*:*:*:*:*:*:* | 4.6.14.8 (excluding) | |
| cpe:2.3:h:netgear:cbr750:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:nbr750_firmware:*:*:*:*:*:*:*:* | 4.6.15.14 (excluding) | |
| cpe:2.3:h:netgear:nbr750:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:rbe370_firmware:*:*:*:*:*:*:*:* | 12.1.3.11 (excluding) | |
| cpe:2.3:h:netgear:rbe370:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:rbe371_firmware:*:*:*:*:*:*:*:* | 12.1.3.11 (excluding) | |
| cpe:2.3:h:netgear:rbe371:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:rbe372_firmware:*:*:*:*:*:*:*:* | 12.1.3.11 (excluding) | |
| cpe:2.3:h:netgear:rbe372:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:rbe373_firmware:*:*:*:*:*:*:*:* | 12.1.3.11 (excluding) | |
| cpe:2.3:h:netgear:rbe373:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:rbe374_firmware:*:*:*:*:*:*:*:* | 12.1.3.11 (excluding) | |
| cpe:2.3:h:netgear:rbe374:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:rbe770_firmware:*:*:*:*:*:*:*:* | 10.5.20.7 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory
- https://www.netgear.com/support/product/cbr750
- https://www.netgear.com/support/product/nbr750
- https://www.netgear.com/support/product/rbe370
- https://www.netgear.com/support/product/rbe371
- https://www.netgear.com/support/product/rbe372
- https://www.netgear.com/support/product/rbe373
- https://www.netgear.com/support/product/rbe374
- https://www.netgear.com/support/product/rbe770
- https://www.netgear.com/support/product/rbe771
- https://www.netgear.com/support/product/rbe772
- https://www.netgear.com/support/product/rbe773
- https://www.netgear.com/support/product/rbe970
- https://www.netgear.com/support/product/rbe971
- https://www.netgear.com/support/product/rbr750
- https://www.netgear.com/support/product/rbr840
- https://www.netgear.com/support/product/rbr850
- https://www.netgear.com/support/product/rbr860
- https://www.netgear.com/support/product/rbre950
- https://www.netgear.com/support/product/rbre960
- https://www.netgear.com/support/product/rbs750
- https://www.netgear.com/support/product/rbs840
- https://www.netgear.com/support/product/rbs850
- https://www.netgear.com/support/product/rbs860
- https://www.netgear.com/support/product/rbse950
- https://www.netgear.com/support/product/rbse960



