An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authenticated administrators connected to the local network can modify router functionality beyond what is intended through the standard management interface. | An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality. |
| Title | RAXE450 and RAXE500 routers allow administrators to modify router functionality beyond intended limits | Improper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionality |
Wed, 10 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear
Netgear raxe450 Netgear raxe500 |
|
| Vendors & Products |
Netgear
Netgear raxe450 Netgear raxe500 |
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authenticated administrators connected to the local network can modify router functionality beyond what is intended through the standard management interface. | |
| Title | RAXE450 and RAXE500 routers allow administrators to modify router functionality beyond intended limits | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NETGEAR
Published: 2026-06-09T15:50:47.870Z
Updated: 2026-06-11T06:02:54.919Z
Reserved: 2025-12-03T04:16:23.205Z
Link: CVE-2026-0416
Updated: 2026-06-09T17:35:12.623Z
Status : Awaiting Analysis
Published: 2026-06-09T17:16:59.313
Modified: 2026-06-11T07:16:26.447
Link: CVE-2026-0416
No data.
ReportizFlow