MEDIUM · 4.5

CVE-2026-0417

Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

Vulnerability Description

Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

CVSS Score

4.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
NetgearMr60 Firmware< 1.1.7.132
NetgearMr60-
NetgearMr70 Firmware< 1.0.3.28
NetgearMr70-
NetgearMr80 Firmware< 1.1.7.14
NetgearMr80-
NetgearMs60 Firmware< 1.1.7.132
NetgearMs60-
NetgearMs70 Firmware< 1.0.3.28
NetgearMs70-
NetgearMs80 Firmware< 1.1.7.14
NetgearMs80-
NetgearR6400V2 Firmware< 1.0.4.128
NetgearR6400V2-
NetgearR6700V3 Firmware< 1.0.4.128
NetgearR6700V3-
NetgearR6900P Firmware< 1.3.3.152
NetgearR6900P-
NetgearR7000 Firmware< 1.0.11.216
NetgearR7000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-0417?

CVE-2026-0417 is a vulnerability with a CVSS score of 4.5 (MEDIUM). Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

How severe is CVE-2026-0417?

CVE-2026-0417 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-0417?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear Mr60 Firmware, Netgear Mr60, Netgear Mr70 Firmware, Netgear Mr70, Netgear Mr80 Firmware.