Cyber Posture

CVE-2026-0407

High

Published: 13 January 2026

Published
13 January 2026
Modified
20 February 2026
KEV Added
Patch
CVSS Score 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0008 22.7th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-0407 is a high-severity Improper Authentication (CWE-287) vulnerability in Netgear Ex5000 Firmware. Its CVSS base score is 8.0 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique External Remote Services (T1133); ranked at the 22.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 AC-14 (Permitted Actions Without Identification or Authentication) and AC-3 (Access Enforcement).

Threat & Defense at a Glance

What attackers do: exploitation maps to External Remote Services (T1133) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly identifies and restricts sensitive actions like admin panel access that can be performed without identification or authentication, mitigating the bypass vulnerability.

prevent

Enforces approved access control policies to prevent unauthorized logical access to the admin panel despite authentication bypass attempts.

prevent

Requires unique identification and authentication for non-organizational users accessing system resources such as the admin panel, addressing the insufficient authentication issue.

MITRE ATT&CK Enterprise TechniquesAI

T1133 External Remote Services Persistence
Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Insufficient authentication bypass directly enables unauthorized access to the device's remote admin/management interface from an adjacent network position.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.

Deeper analysisAI

CVE-2026-0407 is an insufficient authentication vulnerability (CWE-287) in NETGEAR WiFi range extenders, including models such as EX2800, EX3110, EX5000, and EX6110. Published on 2026-01-13, the issue enables attackers to bypass the authentication process and access the admin panel. It carries a CVSS v3.1 base score of 8.0 (AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant impact.

A network-adjacent attacker with WiFi authentication or a physical Ethernet port connection can exploit this vulnerability. The attack requires low complexity and low privileges, with no user interaction needed. Exploitation allows high confidentiality, integrity, and availability impacts, potentially granting unauthorized administrative access to the device.

The NETGEAR Security Advisory provides details on mitigation and patches: https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory. Additional product support pages are available for EX2800 (https://www.netgear.com/support/product/ex2800), EX3110 (https://www.netgear.com/support/product/ex3110), EX5000 (https://www.netgear.com/support/product/ex5000), and EX6110 (https://www.netgear.com/support/product/ex6110).

Details

CWE(s)

Affected Products

netgear
ex5000 firmware
≤ 1.0.1.82
netgear
ex3110 firmware
≤ 1.0.1.82
netgear
ex6110 firmware
≤ 1.0.1.82
netgear
ex2800 firmware
≤ 1.0.1.82

CVEs Like This One

CVE-2026-0408Same product: Netgear Ex2800
CVE-2024-57046Same vendor: Netgear
CVE-2026-0405Same vendor: Netgear
CVE-2024-54809Same vendor: Netgear
CVE-2024-54805Same vendor: Netgear
CVE-2025-50526Same vendor: Netgear
CVE-2024-54803Same vendor: Netgear
CVE-2025-44658Same vendor: Netgear
CVE-2025-7407Same vendor: Netgear
CVE-2025-28219Same vendor: Netgear

References