MEDIUM · 4.5

CVE-2026-0418

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

Vulnerability Description

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

CVSS Score

4.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
NetgearCbr750 Firmware< 4.6.14.4
NetgearCbr750-
NetgearEx6120 Firmware-
NetgearEx6120-
NetgearEx6130 Firmware-
NetgearEx6130-
NetgearMr60 Firmware< 1.1.7.128
NetgearMr60-
NetgearMr70 Firmware< 1.0.3.28
NetgearMr70-
NetgearMr80 Firmware< 1.1.7.6
NetgearMr80-
NetgearMs60 Firmware< 1.1.7.128
NetgearMs60-
NetgearMs70 Firmware< 1.0.3.28
NetgearMs70-
NetgearMs80 Firmware< 1.1.7.6
NetgearMs80-
NetgearRax15 Firmware-
NetgearRax15-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-0418?

CVE-2026-0418 is a vulnerability with a CVSS score of 4.5 (MEDIUM). Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

How severe is CVE-2026-0418?

CVE-2026-0418 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-0418?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear Cbr750 Firmware, Netgear Cbr750, Netgear Ex6120 Firmware, Netgear Ex6120, Netgear Ex6130 Firmware.