CVE-2026-0417
CVE-2026-0417 is a medium-severity vulnerability in Netgear Mr60 Firmware with a CVSS 3.x base score of 4.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Medium (CVSS 3.x base score 4.5)
- CVSS v4: 4.3
- EPSS exploit prediction: 0% (14th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-35460
- Weakness: CWE-20
- Affected product: Netgear Mr60 Firmware
- Published:
- Last modified:
Description
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
Frequently asked questions
- What is CVE-2026-0417?
- Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
- How severe is CVE-2026-0417?
- CVE-2026-0417 has a CVSS 3.x base score of 4.5, rated medium severity. It is exploitable over an adjacent network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2026-0417 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (14th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-0417?
- CVE-2026-0417 primarily affects Netgear Mr60 Firmware. In total, 27 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-0417?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-0417 have an EU (EUVD) identifier?
- Yes. CVE-2026-0417 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-35460.
- When was CVE-2026-0417 published?
- CVE-2026-0417 was published on 2026-06-09 and last updated on 2026-07-23.
References
- https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
- https://www.netgear.com/support/product/mr60/
- https://www.netgear.com/support/product/mr70/
- https://www.netgear.com/support/product/mr80/
- https://www.netgear.com/support/product/ms60/
- https://www.netgear.com/support/product/ms70/
- https://www.netgear.com/support/product/ms80/
- https://www.netgear.com/support/product/r6400v2/
- https://www.netgear.com/support/product/r6700v3/
- https://www.netgear.com/support/product/r6900p/
- https://www.netgear.com/support/product/r7000/
- https://www.netgear.com/support/product/r7000p/
- https://www.netgear.com/support/product/r7960p/
- https://www.netgear.com/support/product/r8000p/
- https://www.netgear.com/support/product/r8500/
- https://www.netgear.com/support/product/rax20/
- https://www.netgear.com/support/product/rax35v2/
- https://www.netgear.com/support/product/rax40v2/
- https://www.netgear.com/support/product/rax41/
- https://www.netgear.com/support/product/rax42/
- https://www.netgear.com/support/product/rax43/
- https://www.netgear.com/support/product/rax45/
- https://www.netgear.com/support/product/rax48/
- https://www.netgear.com/support/product/rax50/
- https://www.netgear.com/support/product/rax50s/
- https://www.netgear.com/support/product/raxe450/
- https://www.netgear.com/support/product/raxe500/
- https://www.netgear.com/support/product/xr1000/
Affected products (27)
- cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:mr70_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:mr80_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:ms70_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:ms80_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:r6400v2_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:r6700v3_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:r6900p_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:r7960p_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:r8000p_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:r8500_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax20_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax35v2_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax40v2_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax41_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax42_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax43_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax45_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax48_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:rax50s_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:raxe450_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:raxe500_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:xr1000_firmware:*:*:*:*:*:*:*:*
More vulnerabilities in Netgear Mr60 Firmware
- CVE-2021-29068 — Critical (CVSS 9.9): Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before…
- CVE-2023-36187 — Critical (CVSS 9.8): Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to…
- CVE-2022-48322 — Critical (CVSS 9.8): NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This…
- CVE-2021-45617 — Critical (CVSS 9.8): Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before…
- CVE-2020-35795 — Critical (CVSS 9.8): Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects AC2100 before…
- CVE-2021-45622 — Critical (CVSS 9.6): Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before…
All CVEs affecting Netgear Mr60 Firmware →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
- CVE-2026-16117 — Critical (CVSS 10.0): Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…
- CVE-2026-48316 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
- CVE-2026-48281 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →