A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory | Vendor Advisory |
| https://www.netgear.com/support/product/rbe372/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
No history.
Information
Published : 2026-06-09 17:16
Updated : 2026-07-23 08:10
NVD link : CVE-2026-0409
Mitre link : CVE-2026-0409
CVE.ORG link : CVE-2026-0409
JSON object : View
Products Affected
netgear
- rbe371
- rbe370_firmware
- rbe371_firmware
- rbe374
- rbe374_firmware
- rbe370
- rbe372
- rbe372_firmware
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
