« Volver al listado

CVE-2026-0411

Estado: AnalizadaMedia (4.2)—

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.

Orbi WiFi Systems without satellite devices are not impacted by this issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-0411",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-0411",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-10T03:59:29.333092Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.1
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 4.2,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "UNREPORTED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "HIGH",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "HIGH",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "HIGH",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
      "affectedData": [
        {
          "vendor": "NETGEAR",
          "product": "RBE970",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "6.3.8.11",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NETGEAR",
          "product": "RBR350",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V4.4.2.2",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NETGEAR",
          "product": "RBR760",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V6.3.8.11",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NETGEAR",
          "product": "RBS350",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V4.4.2.2",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NETGEAR",
          "product": "RBS760",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V6.3.8.11",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-09T17:16:58.453",
  "references": [
    {
      "url": "https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    },
    {
      "url": "https://www.netgear.com/support/product/rbe970/",
      "tags": [
        "Product"
      ],
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    },
    {
      "url": "https://www.netgear.com/support/product/rbr350/",
      "tags": [
        "Product"
      ],
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    },
    {
      "url": "https://www.netgear.com/support/product/rbr760/",
      "tags": [
        "Product"
      ],
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    },
    {
      "url": "https://www.netgear.com/support/product/rbs350/",
      "tags": [
        "Product"
      ],
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    },
    {
      "url": "https://www.netgear.com/support/product/rbs760/",
      "tags": [
        "Product"
      ],
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.\n\n\nOrbi WiFi Systems without satellite devices are not impacted by this issue."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de revelación de información en los satélites NETGEAR Orbi podría permitir a un usuario conectado a su red obtener acceso de administrador al router Orbi. Los modelos NETGEAR listados se ven afectados por esta vulnerabilidad.\n\nLos sistemas WiFi Orbi sin dispositivos satélite no se ven afectados por este problema."
    }
  ],
  "lastModified": "2026-07-23T08:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:rbe970_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3821162-B566-4B42-B210-B7F2B0E39512",
              "versionEndExcluding": "9.13.2.1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:rbe970:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DE1F3088-9598-4EB5-A8A0-E0D4E529CB12"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:rbr350_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15B6577A-EB55-40E2-9B6C-2821923E76E9",
              "versionEndExcluding": "4.4.2.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:rbr350:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C967BD79-D46C-4E73-9063-394454C33180"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:rbr760_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87A60D1D-8933-43AD-8C45-3377B3F02F89",
              "versionEndExcluding": "6.3.8.11"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:rbr760:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "49412019-F011-40A8-B09E-F704E9C343AB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:rbs350_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BCF891A-82B5-45FA-9041-86D2CD05248F",
              "versionEndExcluding": "4.4.2.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:rbs350:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D69C0384-012F-4F3C-B5B2-EE2087C8187D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:rbs760_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B325A884-D98D-40CD-829F-9F75E8028AE1",
              "versionEndExcluding": "6.3.8.11"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:rbs760:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1A648203-25DE-41E9-A7C4-A08F070479D1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "a2826606-91e7-4eb6-899e-8484bd4575d5"
}