CVE-2026-0418
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/R:U/V:D/RE:L/U:Amber
- EPSS probability
- 0.24%
- CWE
- CWE-15
- Published
- 2026-06-09
- Last modified
- 2026-06-10
Affected products
- NETGEAR CBR750
- NETGEAR EX6120
- NETGEAR EX6130
- NETGEAR MR60
- NETGEAR MR70
- NETGEAR MR80
- NETGEAR MS60
- NETGEAR MS70
Weakness type
Related vulnerabilities
- CVE-2026-85217 — Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop
- CVE-2026-19592 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS...
- CVE-2026-19593 — OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree...
- CVE-2026-16708 — IBM Db2 Mirror for i is affected by multiple vulnerabilities
- CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control...
- CVE-2026-73661 — FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
- CVE-2026-66065 — Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211)
- CVE-2026-56567 — HCL iControl is affected by multiple security vulnerabilities.