CVE-2026-0409
Estado: AnalizadaMedia (4.8)—
A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 4.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.26%
- Percentil entre todas las CVEs puntuadas: 16
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-119
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-0409",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-0409",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-06-10T03:59:23.715804Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.5
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 4.8,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "UNREPORTED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "ACTIVE",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
"affectedData": [
{
"vendor": "NETGEAR",
"product": "Orbi 370",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V12.1.2.7",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-09T17:16:58.060",
"references": [
{
"url": "https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory",
"tags": [
"Vendor Advisory"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rbe372/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7."
},
{
"lang": "es",
"value": "Un problema de seguridad de NETGEAR que podría permitir a un atacante con la capacidad de interceptar y manipular el tráfico entre el router e Internet ejecutar comandos en su dispositivo cuando el administrador del dispositivo realiza ciertas acciones de gestión específicas. Este problema afecta a los dispositivos NETGEAR Orbi serie 370 anteriores a la versión V12.1.2.7."
}
],
"lastModified": "2026-07-23T08:10:00.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rbe370_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40EB2E9F-41D9-424D-B0FA-F87BE62AAAFF",
"versionEndExcluding": "12.1.2.7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rbe370:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "368F8D25-16A4-416B-82EC-7508218DD281"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rbe371_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CBBE681-AA97-44FD-A059-E8AE1A5E2388",
"versionEndExcluding": "12.1.2.7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rbe371:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "00BA4811-2DD1-4DA6-8ECF-CFFEFCB443F2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rbe372_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B44F937-7A16-4139-8943-3BFA0480851F",
"versionEndExcluding": "12.1.2.7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rbe372:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7FA875C8-A4CC-4CC6-8681-803C6F244E36"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rbe374_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C88D3308-C6FA-4455-8DB5-584AACA9B442",
"versionEndExcluding": "12.1.2.7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rbe374:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A4B041C8-A297-478F-86A0-91769750F7B9"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "a2826606-91e7-4eb6-899e-8484bd4575d5"
}