Impact
The vulnerability allows any user connected to the local network to access the router’s web interface as an administrator. Because this access grants the ability to change router configuration, it is inferred that an attacker could modify routing, security, or network settings, potentially impacting confidentiality, integrity, and availability of the network.
Affected Systems
Affected models are the NETGEAR Orbi Access Point CBR750 and Orbi Router NBR750, the Orbi Xtreme series RBE370 through RBE374 and RBE770 through RBE773, the RBE970–RBE971 line, and the corresponding router variants RBR750–RBR860, RBS750–RBS860, RBRE950–RBRE960, and RBSE950–RBSE960. Devices are impacted unless they are running one of the firmware versions listed in the advisory: CBR750 V4.6.14.8 or later, NBR750 V4.6.15.14 or later, RBE370–RBE374 V12.1.3.11 or later, RBE770–RBE773 V10.5.20.7 or later, RBE970–RBE971 V9.13.2.1 or later, and all RBR, RBS, RBRE, and RBSE models V7.2.8.2 or later.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to be on the same local network as the device, so the threat is limited to physically present or compromised clients within that LAN. No publicly available exploit code is indicated, and the low EPSS further suggests a limited chance of widespread exploitation.
OpenCVE Enrichment