ID

VAR-202606-2758


CVE

CVE-2026-0412


TITLE

of netgear JR6150  Firmware Input Validation Vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2026-020459

DESCRIPTION

Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality.  NETGEAR JR6150 reached End-of-Support status in 2018 and is no longer receiving security updates. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware. • All information handled by this software may be overwritten. • This software will not stop

Trust: 1.62

sources: NVD: CVE-2026-0412 // JVNDB: JVNDB-2026-020459

AFFECTED PRODUCTS

vendor:ネットギアmodel:jr6150scope:eqversion: -

Trust: 0.8

vendor:ネットギアmodel:jr6150scope:eqversion:jr6150 firmware

Trust: 0.8

vendor:ネットギアmodel:jr6150scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-020459

CVSS

SEVERITY

CVSSV2

CVSSV3

a2826606-91e7-4eb6-899e-8484bd4575d5: CVE-2026-0412
value: MEDIUM

Trust: 1.0

NVD: CVE-2026-0412
value: MEDIUM

Trust: 0.8

NVD: CVE-2026-0412
baseSeverity: MEDIUM
baseScore: 4.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-020459 // NVD: CVE-2026-0412

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.0

problemtype:Inappropriate input confirmation (CWE-20) [ others ]

Trust: 0.8

problemtype: Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-020459 // NVD: CVE-2026-0412

PATCH

title:June 2026 NETGEAR Security Advisory - NETGEAR Supporturl:https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory

Trust: 0.8

sources: JVNDB: JVNDB-2026-020459

EXTERNAL IDS

db:NVDid:CVE-2026-0412

Trust: 2.6

db:JVNDBid:JVNDB-2026-020459

Trust: 0.8

sources: JVNDB: JVNDB-2026-020459 // NVD: CVE-2026-0412

REFERENCES

url:https://www.netgear.com/support/product/jr6150

Trust: 1.8

url:https://kb.netgear.com/000070811/june-2026-netgear-security-advisory

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-0412

Trust: 0.8

sources: JVNDB: JVNDB-2026-020459 // NVD: CVE-2026-0412

SOURCES

db:JVNDBid:JVNDB-2026-020459
db:NVDid:CVE-2026-0412

LAST UPDATE DATE

2026-06-25T23:20:20.908000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-020459date:2026-06-22T02:45:00
db:NVDid:CVE-2026-0412date:2026-06-10T16:16:55.707

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-020459date:2026-06-22T00:00:00
db:NVDid:CVE-2026-0412date:2026-06-09T17:16:58.627