Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
History

Thu, 11 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution vulnerability exists in RBE970 Insufficient Input Validation Allows Unauthorized Modification of Router Software in certain NETGEAR Routers

Wed, 10 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
References

Tue, 09 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear rbe97x
Vendors & Products Netgear
Netgear rbe97x

Tue, 09 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Description Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
Title Arbitrary Code Execution vulnerability exists in RBE970
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published: 2026-06-09T15:50:51.171Z

Updated: 2026-06-11T05:32:52.140Z

Reserved: 2025-12-03T04:16:21.302Z

Link: CVE-2026-0414

cve-icon Vulnrichment

Updated: 2026-06-09T17:05:09.581Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:16:58.990

Modified: 2026-06-10T14:16:30.967

Link: CVE-2026-0414

cve-icon Redhat

No data.