Cyber Resilience

CVE-2026-0413

Memory Safety in Netgear Rbe370 Firmware ≤ 12.1.2.1

Published
09 June 2026
Modified
18 June 2026
Patch / advisory
CVSS Score v4 4.3
Click a component to see what it means
Raw vectorCVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0032 25th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2026-0413 is a medium-severity Stack-based Buffer Overflow (CWE-121) vulnerability in Netgear Rbe370 Firmware. Its CVSS base score is 4.3 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 25th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and SI-16 (Memory Protection) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

Buffer overflow (CWE-121) in authenticated admin interface directly enables code execution for privilege escalation on the device.

Confidence: MEDIUM · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2026-0404Same product: Netgear Rbr750
CVE-2026-0405Same product: Netgear Rbe370
CVE-2026-0415Same product: Netgear Rbr750
CVE-2024-54808Same vendor: Netgear
CVE-2026-0403Same product: Netgear Rbr750
CVE-2024-54809Same vendor: Netgear
CVE-2025-52080Same vendor: Netgear
CVE-2025-52081Same vendor: Netgear
CVE-2020-10924Same vendor: Netgear
CVE-2025-52082Same vendor: Netgear

Affected Assets

netgear
rbe370 firmware
≤ 12.1.2.1
netgear
rbe770 firmware
≤ 10.5.20.10
netgear
rbr750 firmware
≤ 7.2.8.5
netgear
rbr840 firmware
≤ 7.2.8.5
netgear
rbr850 firmware
≤ 7.2.8.5
netgear
rbr860 firmware
≤ 7.2.8.5
netgear
rbre950 firmware
≤ 7.2.8.5
netgear
rbre960 firmware
≤ 7.2.8.5
netgear
rbs750 firmware
≤ 7.2.8.5
netgear
rbs840 firmware
≤ 7.2.8.5
+4 more product configuration(s) — see NVD for full list

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • SI-10 Information Input Validation
  • SI-16 Memory Protection
Detect
Catch it (NIST detect / respond)
  • SI-7 Software, Firmware, and Information Integrity
Harden
Shrink the surface (DISA STIG)
  • 2 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly requires validation of all inputs to prevent malformed data from triggering the stack buffer overflow (CWE-121).

prevent

Enforces memory protections (e.g., ASLR, stack canaries, NX) that block exploitation of the buffer overflow even if input validation fails.

detect

Requires integrity verification of firmware and software, detecting unauthorized modifications resulting from successful exploitation.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure-development practices directly prevent introduction of stack buffer overflows.

ID.RA-01 partial match
prevents

Vulnerability scanning can discover stack buffer overflows but does not prevent their introduction.

PR.PS-02 partial match
prevents

Patching eliminates known instances of the weakness after discovery.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

detects

Security testing (fuzzing, static analysis) detects stack overflows before release.

prevents

Secure SDLC mandates buffer-safety practices that directly prevent stack overflows.

prevents

Application security requirements can specify buffer-size and input-validation rules.

prevents

Secure architecture principles include memory-safety and least-privilege stack usage.

prevents

Secure coding standards explicitly forbid unsafe buffer handling that causes CWE-121.

none

Change-management gates can enforce security reviews that catch buffer issues.

References