CVE-2026-3088
Analyzed
Analyzed - Analysis Complete
Denial of Service in Router Firmware
Vulnerability report for CVE-2026-3088, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-06-09
Last updated on: 2026-06-18
Assigner: Netgear, Inc.
Description
Description
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netgear | rbe970_firmware | to 9.10.1.4 (exc) |
| netgear | rbe971_firmware | to 9.10.1.4 (exc) |
| netgear | rbr860_firmware | to 7.2.7.15 (exc) |
| netgear | rbre950_firmware | to 7.2.7.15 (exc) |
| netgear | rbre960_firmware | to 7.2.7.15 (exc) |
| netgear | rbs860_firmware | to 7.2.7.15 (exc) |
| netgear | rbse950_firmware | to 7.2.7.15 (exc) |
| netgear | rbse960_firmware | to 7.2.7.15 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |