{"api_version":"1","generated_at":"2026-06-10T20:53:40+00:00","cve":"CVE-2026-0411","urls":{"html":"https://cve.report/CVE-2026-0411","api":"https://cve.report/api/cve/CVE-2026-0411.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-0411","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-0411"},"summary":{"title":"A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi Satellites","description":"An information disclosure vulnerability in the NETGEAR Orbi satellites could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.\n\n\nOrbi WiFi Systems without satellite devices are not impacted by this issue.","state":"PUBLISHED","assigner":"NETGEAR","published_at":"2026-06-09 17:16:58","updated_at":"2026-06-10 14:16:30"},"problem_types":["CWE-200","CWE-200 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor"],"metrics":[{"version":"4.0","source":"a2826606-91e7-4eb6-899e-8484bd4575d5","type":"Secondary","score":"4.2","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"4.2","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":4.2,"baseSeverity":"MEDIUM","exploitMaturity":"UNREPORTED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory","name":"https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory","refsource":"a2826606-91e7-4eb6-899e-8484bd4575d5","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.netgear.com/support/product/rbe970/","name":"https://www.netgear.com/support/product/rbe970/","refsource":"a2826606-91e7-4eb6-899e-8484bd4575d5","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.netgear.com/support/product/rbr350/","name":"https://www.netgear.com/support/product/rbr350/","refsource":"a2826606-91e7-4eb6-899e-8484bd4575d5","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.netgear.com/support/product/rbr760/","name":"https://www.netgear.com/support/product/rbr760/","refsource":"a2826606-91e7-4eb6-899e-8484bd4575d5","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.netgear.com/support/product/rbs350/","name":"https://www.netgear.com/support/product/rbs350/","refsource":"a2826606-91e7-4eb6-899e-8484bd4575d5","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.netgear.com/support/product/rbs760/","name":"https://www.netgear.com/support/product/rbs760/","refsource":"a2826606-91e7-4eb6-899e-8484bd4575d5","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-0411","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0411","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"NETGEAR","product":"RBE970","version":"affected 6.3.8.11 custom","platforms":[]},{"source":"CNA","vendor":"NETGEAR","product":"RBR350","version":"affected V4.4.2.2 custom","platforms":[]},{"source":"CNA","vendor":"NETGEAR","product":"RBR760","version":"affected V6.3.8.11 custom","platforms":[]},{"source":"CNA","vendor":"NETGEAR","product":"RBS350","version":"affected V4.4.2.2 custom","platforms":[]},{"source":"CNA","vendor":"NETGEAR","product":"RBS760","version":"affected V6.3.8.11 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"NETGEAR strongly recommends that you install the latest firmware as soon as possible.\n\n\n\nIssue fixed in:\n\nProductFixed VersionRBE970 Orbi Quad-band Mesh WiFi 7 Add-on Satellite 6.3.8.11 https://www.netgear.com/support/product/rbe970/ RBR350 Orbi AX1800 WiFi 6 Dual-band Mesh Router V4.4.2.2 https://www.netgear.com/support/product/rbr350/ RBR760 Orbi Tri-Band Mesh WiFi 6 Router V6.3.8.11 https://www.netgear.com/support/product/rbr760/ RBS350 Orbi AX1800 WiFi 6 Dual-band Mesh Add-on Satellite V4.4.2.2 https://www.netgear.com/support/product/rbs350/ RBS760 Orbi Tri-Band Mesh WiFi 6 Add-on Satellite V6.3.8.11 https://www.netgear.com/support/product/rbs760/","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-0411","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-06-09T00:00:00+00:00","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-06-10T03:59:28.558Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"RBE970","vendor":"NETGEAR","versions":[{"lessThan":"6.3.8.11","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"RBR350","vendor":"NETGEAR","versions":[{"lessThan":"V4.4.2.2","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"RBR760","vendor":"NETGEAR","versions":[{"lessThan":"V6.3.8.11","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"RBS350","vendor":"NETGEAR","versions":[{"lessThan":"V4.4.2.2","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"RBS760","vendor":"NETGEAR","versions":[{"lessThan":"V6.3.8.11","status":"affected","version":"0","versionType":"custom"}]}],"datePublic":"2026-06-09T00:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"An information disclosure vulnerability in the&nbsp;NETGEAR&nbsp;Orbi satellites could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.<div><br></div><div>Orbi WiFi Systems without satellite devices are not impacted by this issue.</div>"}],"value":"An information disclosure vulnerability in the NETGEAR Orbi satellites could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.\n\n\nOrbi WiFi Systems without satellite devices are not impacted by this issue."}],"impacts":[{"descriptions":[{"lang":"en","value":"Sensitive Information Disclosure"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":4.2,"baseSeverity":"MEDIUM","exploitMaturity":"UNREPORTED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-10T12:22:16.700Z","orgId":"a2826606-91e7-4eb6-899e-8484bd4575d5","shortName":"NETGEAR"},"references":[{"tags":["product","patch"],"url":"https://www.netgear.com/support/product/rbr350/"},{"tags":["product","patch"],"url":"https://www.netgear.com/support/product/rbs760/"},{"tags":["product","patch"],"url":"https://www.netgear.com/support/product/rbs350/"},{"tags":["product","patch"],"url":"https://www.netgear.com/support/product/rbr760/"},{"tags":["product","patch"],"url":"https://www.netgear.com/support/product/rbe970/"},{"tags":["vendor-advisory"],"url":"https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>NETGEAR strongly recommends that you install the latest firmware as soon as possible.</p><p>Issue fixed in:</p><table><thead><tr><th>Product</th><th>Fixed Version</th></tr></thead><tbody><tr><td><b>RBE970</b> Orbi Quad-band Mesh WiFi 7 Add-on Satellite</td><td><a href=\"https://www.netgear.com/support/product/rbe970/\">6.3.8.11</a></td></tr><tr><td><b>RBR350</b> Orbi AX1800 WiFi 6 Dual-band Mesh Router</td><td><a href=\"https://www.netgear.com/support/product/rbr350/\">V4.4.2.2</a></td></tr><tr><td><b>RBR760</b> Orbi Tri-Band Mesh WiFi 6 Router</td><td><a href=\"https://www.netgear.com/support/product/rbr760/\">V6.3.8.11</a></td></tr><tr><td><b>RBS350</b> Orbi AX1800 WiFi 6 Dual-band Mesh Add-on Satellite</td><td><a href=\"https://www.netgear.com/support/product/rbs350/\">V4.4.2.2</a></td></tr><tr><td><b>RBS760</b> Orbi Tri-Band Mesh WiFi 6 Add-on Satellite</td><td><a href=\"https://www.netgear.com/support/product/rbs760/\">V6.3.8.11</a></td></tr></tbody></table>"}],"value":"NETGEAR strongly recommends that you install the latest firmware as soon as possible.\n\n\n\nIssue fixed in:\n\nProductFixed VersionRBE970 Orbi Quad-band Mesh WiFi 7 Add-on Satellite 6.3.8.11 https://www.netgear.com/support/product/rbe970/ RBR350 Orbi AX1800 WiFi 6 Dual-band Mesh Router V4.4.2.2 https://www.netgear.com/support/product/rbr350/ RBR760 Orbi Tri-Band Mesh WiFi 6 Router V6.3.8.11 https://www.netgear.com/support/product/rbr760/ RBS350 Orbi AX1800 WiFi 6 Dual-band Mesh Add-on Satellite V4.4.2.2 https://www.netgear.com/support/product/rbs350/ RBS760 Orbi Tri-Band Mesh WiFi 6 Add-on Satellite V6.3.8.11 https://www.netgear.com/support/product/rbs760/"}],"source":{"discovery":"EXTERNAL"},"title":"A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi Satellites","x_generator":{"engine":"Vulnogram 1.0.3"}}},"cveMetadata":{"assignerOrgId":"a2826606-91e7-4eb6-899e-8484bd4575d5","assignerShortName":"NETGEAR","cveId":"CVE-2026-0411","datePublished":"2026-06-09T15:50:52.418Z","dateReserved":"2025-12-03T04:16:18.239Z","dateUpdated":"2026-06-10T12:22:16.700Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-09 17:16:58","lastModifiedDate":"2026-06-10 14:16:30","problem_types":["CWE-200","CWE-200 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor"],"metrics":{"cvssMetricV40":[{"source":"a2826606-91e7-4eb6-899e-8484bd4575d5","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"411","Ordinal":"1","Title":"A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi","CVE":"CVE-2026-0411","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"411","Ordinal":"1","NoteData":"An information disclosure vulnerability in the NETGEAR Orbi satellites could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.\n\n\nOrbi WiFi Systems without satellite devices are not impacted by this issue.","Type":"Description","Title":"A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi"}]}}}