Description
A
security flaw was found in certain NETGEAR Orbi models that
could allow an unauthorized user to cause the device to stop responding or
restart unexpectedly, disrupting network connectivity and making the device
temporarily unavailable.
Published: 2026-07-14
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack overflow in the firmware of specific NETGEAR Orbi routers that leads to a denial of service, allowing an unauthorized user to cause the device to become unresponsive or reboot, disrupting network connectivity and temporarily denying access to the device.

Affected Systems

Affected devices include the NETGEAR Orbi RBE970, RBE971, RBR860, RBRE950, RBRE960, RBS860, RBSE950, and RBSE960 models. The flaw was present in the default firmware before version V9.10.1.4 for the RBE970 and RBE971, and before V7.2.7.15 for the RBR860, RBRE950, RBRE960, RBS860, RBSE950, and RBSE960. Firmware updates to these listed versions contain a patch that resolves the stack overflow.

Risk and Exploitability

The CVSS score is 5.7, indicating moderate severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network-based, where an attacker with network access can trigger the stack overflow, potentially by sending malformed packets to the affected service. No additional prerequisites are mentioned, and the flaw can be exploited remotely if the network is not securely segmented.

Generated by OpenCVE AI on August 1, 2026 at 09:25 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionRBE970 Orbi Quad-band Mesh WiFi 7 Add-on Satellite V9.10.1.4 https://www.netgear.com/support/product/rbe970/ RBE971 Orbi Quad-band Mesh WiFi 7 Router V9.10.1.4 https://www.netgear.com/support/product/rbe971/ RBR860 Orbi Tri-band Mesh WiFi 6 Router – 860 Series V7.2.7.15 https://www.netgear.com/support/product/rbr860/ RBRE950 Orbi Quad-band Mesh WiFi 6E Router v7.2.7.15 https://www.netgear.com/support/product/rbre950/ RBRE960 Orbi Quad-band Mesh WiFi 6E Router V7.2.7.15 https://www.netgear.com/support/product/rbre960/ RBS860 Orbi Tri-band Mesh WiFi 6 Add-on Satellite – 860 Series V7.2.7.15 https://www.netgear.com/support/product/rbs860/ RBSE950 Orbi Quad-band Mesh WiFi 6E Add-on Satellite v7.2.7.15 https://www.netgear.com/support/product/rbse950/ RBSE960 Orbi Quad-band Mesh WiFi 6E Add-on Satellite V7.2.7.15 https://www.netgear.com/support/product/rbse960/


OpenCVE Recommended Actions

  • Upgrade the firmware to the latest fixed version for each device
  • Enable automatic firmware updates to keep the device patched
  • If an update is not yet available, isolate the device from untrusted networks or block the port that exposes the vulnerable service
  • Monitor device logs for abnormal restarts or connectivity loss

Generated by OpenCVE AI on August 1, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear rbe970
Netgear rbe971
Netgear rbr860
Netgear rbre950
Netgear rbre960
Netgear rbs860
Netgear rbse950
Netgear rbse960
Vendors & Products Netgear
Netgear rbe970
Netgear rbe971
Netgear rbr860
Netgear rbre950
Netgear rbre960
Netgear rbs860
Netgear rbse950
Netgear rbse960

Wed, 15 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
References

Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable.
Title A DoS vulnerability due to stack overflow exists in certain NETGEAR Orbi models
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-07-15T16:52:24.542Z

Reserved: 2026-07-14T16:31:02.508Z

Link: CVE-2026-62655

cve-icon Vulnrichment

Updated: 2026-07-15T14:46:54.565Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:30:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow