ZeroHour

CVE-2026-0406

CVSS 4.0
6.1 medium
EPSS
<1%p12
Published
()
Modified
Description

An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections.

Vendors
netgear
Products
xr1000v2 firmware
Weakness
CWE-20
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Amber

In the news

No ingested article mentions this CVE yet.