extenders allows a network adjacent attacker with WiFi authentication or
a physical Ethernet port connection to bypass the authentication
process and access the admin panel.
Project Subscriptions
No advisories yet.
Solution
Manually check the firmware version and update it to the latest. Fixed in: EX2800 firmware V1.0.1.82 or later https://www.netgear.com/support/product/ex2800 EX3110 firmware V1.0.1.82 or later https://www.netgear.com/support/product/ex3110 EX5000 firmware V1.0.1.82 or later https://www.netgear.com/support/product/ex5000 EX6110 firmware V1.0.1.82 or later https://www.netgear.com/support/product/ex6110
Workaround
No workaround given by the vendor.
Tue, 13 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 13 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel. | |
| Title | Authentication bypass in NETGEAR WiFi Range Extenders via network adjacent attacks | |
| First Time appeared |
Netgear
Netgear ex2800 Netgear ex3110 Netgear ex5000 Netgear ex6110 |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:h:netgear:ex2800:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex3110:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex5000:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ex6110:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgear
Netgear ex2800 Netgear ex3110 Netgear ex5000 Netgear ex6110 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NETGEAR
Published:
Updated: 2026-01-14T04:57:23.822Z
Reserved: 2025-12-03T04:16:13.882Z
Link: CVE-2026-0407
Updated: 2026-01-13T18:47:37.449Z
Status : Awaiting Analysis
Published: 2026-01-13T16:16:10.840
Modified: 2026-01-14T16:25:40.430
Link: CVE-2026-0407
No data.
OpenCVE Enrichment
No data.