Netgear Products Insufficient Configuration Management Vulnerability Allowing Tampering by Authenticated Administrators

Vulnerability

A vulnerability exists in various Netgear devices due to inadequate configuration management. This issue enables authenticated administrators connected to the local network to manipulate the system. Affected products include the Orbi WiFi 6 Router AX4200 (CBR750), Orbi WiFi 6 Add-on Satellite (MS60), Nighthawk Mesh WiFi 6 Router (MR70), Nighthawk Tri-band Mesh WiFi 6 Router (MR80), Nighthawk AX4 4-Stream AX3000 WiFi 6 Router (RAX35v2), Nighthawk AX5 5-Stream AX4200 WiFi Router (RAX40v2), Nighthawk AX6 6-Stream AX4300 WiFi Router (RAX45), Nighthawk AX6 6-Stream AX5400 WiFi 6 Router (RAX50), Nighthawk AX6 6-Stream AX5400 WiFi 6 Router (RAX50S), Nighthawk AX8 8-Stream AX5700 WiFi 6 Router (RAX75), Nighthawk AX8 8-Stream AX6000 WiFi 6 Router (RAX80), Nighthawk AXE10000 Tri-Band WiFi 6E Router (RAXE450), Nighthawk AXE10000 Tri-Band WiFi 6E Router (RAXE500), Orbi Quad-band Mesh WiFi 6E Router (RBRE960), Orbi WiFi 6 Router AX6000 (RBR850), Orbi WiFi 6 System AX5700 (RBR840), Orbi WiFi 6 Add-on Satellite AX5700 (RBS840) and Orbi WiFi 6 Add-on Satellite AX4200 (RBS750).

Impact

This vulnerability could lead to unauthorized system modifications by authenticated administrators on the local network.

Remediation

Users can update to the latest firmware version available for their specific Netgear device. Instructions for downloading the firmware can be found on the Netgear Download Center.

Added: Jun 9, 2026, 9:10 PM
Updated: Jun 9, 2026, 9:10 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
3.0
remediation
7.7
relevance
9.4
threat
0.0
urgency
5.7
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.