CVE-2026-0416
בינונית 4.5
תיאור (מקור, אנגלית)
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.
מדדים
- CVSS 3.1
-
4.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N - CVSS 4.0
-
4.3 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-9/8/2026
- CWE
- CWE-20
מוצרים מושפעים
netgear: raxe450 firmware; netgear: raxe450; netgear: raxe500 firmware; netgear: raxe500