Netgear Router Admin Auth Escalation via Local Net
CVE-2026-0410 Published on June 9, 2026

Insufficient input validation in certain NETGEAR routers
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.

NVD

Weakness Type

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


Affected Versions

NETGEAR R7000: NETGEAR RAX20: NETGEAR RAX35v2: NETGEAR RAX41: NETGEAR RAX41v2: NETGEAR RAX42: NETGEAR RAX42v2: NETGEAR RAX43: NETGEAR RAX43v2: NETGEAR RAX45: NETGEAR RAX49S: NETGEAR RAX50: NETGEAR RAX50S: NETGEAR RAX50v2: NETGEAR RAX54Sv2: NETGEAR RAX54v2: NETGEAR RAXE450: NETGEAR RAXE500: NETGEAR XR1000: NETGEAR XR1000v2: