CVE-2026-0416 MEDIUM

CVE-2026-0416: Improper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionality

Vendor Netgear
Product RAXE450
Weakness CWE-20 · Input validation
Published June 9, 2026
Last update June 11, 2026

CVSS base score

4.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber

What the vulnerability does

01Description

An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.

Key dates

02Disclosure timeline

June 9, 2026 CVE published
June 11, 2026 Record updated