Cyber Posture

CVE-2026-0404

High

Published: 13 January 2026

Published
13 January 2026
Modified
12 February 2026
KEV Added
Patch
CVSS Score 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0015 34.9th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-0404 is a high-severity Improper Input Validation (CWE-20) vulnerability in Netgear Rbr750 Firmware. Its CVSS base score is 8.0 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation of Remote Services (T1210); ranked at the 34.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 CM-7 (Least Functionality) and SI-10 (Information Input Validation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation of Remote Services (T1210) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

SI-10 directly mandates input validation for external interfaces like DHCPv6, preventing command injection from insufficiently validated inputs.

prevent

SI-2 requires timely flaw remediation through firmware patching, directly addressing the known input validation vulnerability in NETGEAR Orbi DHCPv6.

prevent

CM-7 enforces least functionality by disabling non-essential DHCPv6 on Orbi routers, eliminating exposure to the vulnerable feature.

MITRE ATT&CK Enterprise TechniquesAI

T1210 Exploitation of Remote Services Lateral Movement
Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
T1059.004 Unix Shell Execution
Adversaries may abuse Unix shell commands and scripts for execution.
Why these techniques?

Vulnerability directly enables remote exploitation of DHCPv6 service for OS command injection, mapping to remote service exploitation and Unix shell command execution on the router.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

Deeper analysisAI

CVE-2026-0404 is an insufficient input validation vulnerability (CWE-20) in the DHCPv6 functionality of NETGEAR Orbi devices, including models RBR750, RBR840, RBR850, and RBR860. Published on January 13, 2026, this flaw enables OS command injection on the router. It carries a CVSS v3.1 base score of 8.0 (AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), reflecting high impact potential when exploited.

Network-adjacent attackers authenticated over WiFi or on the LAN can exploit the vulnerability by targeting the DHCPv6 feature, which is not enabled by default. Successful exploitation allows execution of arbitrary OS commands on the router, potentially leading to full compromise with high confidentiality, integrity, and availability impacts.

NETGEAR's January 2026 Security Advisory provides details on the vulnerability at https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory, with product support pages available for RBR750, RBR840, RBR850, and RBR860 at their respective URLs. Security practitioners should review these resources for recommended patches and mitigation guidance.

Details

CWE(s)

Affected Products

netgear
rbr750 firmware
≤ 7.2.8.5
netgear
rbr840 firmware
≤ 7.2.8.5
netgear
rbr850 firmware
≤ 7.2.8.5
netgear
rbr860 firmware
≤ 7.2.8.5
netgear
rbs750 firmware
≤ 7.2.8.5
netgear
rbs840 firmware
≤ 7.2.8.5
netgear
rbs850 firmware
≤ 7.2.8.5
netgear
rbs860 firmware
≤ 7.2.8.5
netgear
rbre950 firmware
≤ 7.2.8.5
netgear
rbre960 firmware
≤ 7.2.8.5
+2 more product configuration(s) — see NVD for full list

CVEs Like This One

CVE-2026-0403Same product: Netgear Rbr750
CVE-2026-0406Same vendor: Netgear
CVE-2026-0405Same product: Netgear Rbr750
CVE-2024-54803Same vendor: Netgear
CVE-2025-28219Same vendor: Netgear
CVE-2024-54804Same vendor: Netgear
CVE-2024-54808Same vendor: Netgear
CVE-2024-54805Same vendor: Netgear
CVE-2025-50526Same vendor: Netgear
CVE-2024-54802Same vendor: Netgear

References