VulnerabilityAnalyzed
CVE-2026-0408
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to…
MEDIUM 6.1EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
- CVSS 4.0
- 6.1 MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- netgear/ex2800 firmware · netgear/ex3110 firmware · netgear/ex5000 firmware · netgear/ex6110 firmware
- Source
- a2826606-91e7-4eb6-899e-8484bd4575d5
References
- https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-AdvisoryPatch, Vendor Advisory
- https://www.netgear.com/support/product/ex2800Patch, Product
- https://www.netgear.com/support/product/ex3110Patch, Product
- https://www.netgear.com/support/product/ex5000Patch, Product
- https://www.netgear.com/support/product/ex6110Patch, Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.