CVE-2026-0411
Analyzed
Analyzed - Analysis Complete
Information Disclosure in NETGEAR Orbi Satellites
Vulnerability report for CVE-2026-0411, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-06-09
Last updated on: 2026-06-18
Assigner: Netgear, Inc.
Description
Description
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.
Orbi WiFi Systems without satellite devices are not impacted by this issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netgear | rbe970_firmware | to 9.13.2.1 (exc) |
| netgear | rbr350_firmware | to 4.4.2.2 (exc) |
| netgear | rbr760_firmware | to 6.3.8.11 (exc) |
| netgear | rbs350_firmware | to 4.4.2.2 (exc) |
| netgear | rbs760_firmware | to 6.3.8.11 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |