Vulnerability Description
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Mr60 Firmware | < 1.1.7.132 |
| Netgear | Mr60 | - |
| Netgear | Mr70 Firmware | < 1.0.3.28 |
| Netgear | Mr70 | - |
| Netgear | Mr80 Firmware | < 1.1.7.14 |
| Netgear | Mr80 | - |
| Netgear | Ms60 Firmware | < 1.1.7.132 |
| Netgear | Ms60 | - |
| Netgear | Ms70 Firmware | < 1.0.3.28 |
| Netgear | Ms70 | - |
| Netgear | Ms80 Firmware | < 1.1.7.14 |
| Netgear | Ms80 | - |
| Netgear | R6400V2 Firmware | < 1.0.4.128 |
| Netgear | R6400V2 | - |
| Netgear | R6700V3 Firmware | < 1.0.4.128 |
| Netgear | R6700V3 | - |
| Netgear | R6900P Firmware | < 1.3.3.152 |
| Netgear | R6900P | - |
| Netgear | R7000 Firmware | < 1.0.11.216 |
| Netgear | R7000 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-AdvisoryVendor Advisory
- https://www.netgear.com/support/product/mr60/Product
- https://www.netgear.com/support/product/mr70/Product
- https://www.netgear.com/support/product/mr80/Product
- https://www.netgear.com/support/product/ms60/Product
- https://www.netgear.com/support/product/ms70/Product
- https://www.netgear.com/support/product/ms80/Product
- https://www.netgear.com/support/product/r6400v2/Product
- https://www.netgear.com/support/product/r6700v3/Product
- https://www.netgear.com/support/product/r6900p/Product
- https://www.netgear.com/support/product/r7000/Product
- https://www.netgear.com/support/product/r7000p/Product
- https://www.netgear.com/support/product/r7960p/Product
- https://www.netgear.com/support/product/r8000p/Product
- https://www.netgear.com/support/product/r8500/Product
FAQ
What is CVE-2026-0417?
CVE-2026-0417 is a vulnerability with a CVSS score of 4.5 (MEDIUM). Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
How severe is CVE-2026-0417?
CVE-2026-0417 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-0417?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Mr60 Firmware, Netgear Mr60, Netgear Mr70 Firmware, Netgear Mr70, Netgear Mr80 Firmware.