An insufficient authentication vulnerability in NETGEAR WiFi range
extenders allows a network adjacent attacker with WiFi authentication or
a physical Ethernet port connection to bypass the authentication
process and access the admin panel.

Project Subscriptions

Vendors Products
Netgear Subscribe
Ex2800 Firmware Subscribe
Ex3110 Firmware Subscribe
Ex5000 Firmware Subscribe
Ex6110 Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

Manually check the firmware version and update it to the latest. Fixed in: EX2800  firmware V1.0.1.82 or later https://www.netgear.com/support/product/ex2800 EX3110  firmware V1.0.1.82 or later https://www.netgear.com/support/product/ex3110 EX5000 firmware V1.0.1.82 or later https://www.netgear.com/support/product/ex5000 EX6110  firmware V1.0.1.82 or later https://www.netgear.com/support/product/ex6110


Workaround

No workaround given by the vendor.

History

Fri, 20 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear ex2800 Firmware
Netgear ex3110 Firmware
Netgear ex5000 Firmware
Netgear ex6110 Firmware
CPEs cpe:2.3:h:netgear:ex2800:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6110:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex2800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex3110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex6110_firmware:*:*:*:*:*:*:*:*
Vendors & Products Netgear ex2800 Firmware
Netgear ex3110 Firmware
Netgear ex5000 Firmware
Netgear ex6110 Firmware
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 13 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 16:30:00 +0000


Tue, 13 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Description An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.
Title Authentication bypass in NETGEAR WiFi Range Extenders via network adjacent attacks
First Time appeared Netgear
Netgear ex2800
Netgear ex3110
Netgear ex5000
Netgear ex6110
Weaknesses CWE-287
CPEs cpe:2.3:h:netgear:ex2800:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3110:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex5000:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6110:*:*:*:*:*:*:*:*
Vendors & Products Netgear
Netgear ex2800
Netgear ex3110
Netgear ex5000
Netgear ex6110
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-01-14T04:57:23.822Z

Reserved: 2025-12-03T04:16:13.882Z

Link: CVE-2026-0407

cve-icon Vulnrichment

Updated: 2026-01-13T18:47:37.449Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-13T16:16:10.840

Modified: 2026-02-20T19:40:59.627

Link: CVE-2026-0407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses