VulnerabilityAnalyzed
CVE-2026-0411
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router.
MEDIUM 4.2EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this issue.
- CVSS 4.0
- 4.2 MEDIUMCVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- netgear/rbe970 firmware · netgear/rbr350 firmware · netgear/rbr760 firmware · netgear/rbs350 firmware · netgear/rbs760 firmware
- Source
- a2826606-91e7-4eb6-899e-8484bd4575d5
References
- https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-AdvisoryVendor Advisory
- https://www.netgear.com/support/product/rbe970/Product
- https://www.netgear.com/support/product/rbr350/Product
- https://www.netgear.com/support/product/rbr760/Product
- https://www.netgear.com/support/product/rbs350/Product
- https://www.netgear.com/support/product/rbs760/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.