CVE-2026-0418

Enriched by CISA Privilege Escalation Path Traversal Local Execution Code
 

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
https://nvd.nist.gov/vuln/detail/CVE-2026-0418

Categories

CWE-15 : External Control of System or Configuration Setting
Allowing external control of system settings can disrupt service or cause an application to behave in unexpected, and potentially malicious ways.

References

a2826606-91e7-4eb6-899e-8484bd4575d5

https://www.netgear.com/support/product/cbr750/
https://www.netgear.com/support/product/ex6120/
https://www.netgear.com/support/product/ex6130/
https://www.netgear.com/support/product/mr60/
https://www.netgear.com/support/product/mr70/
https://www.netgear.com/support/product/mr80/
https://www.netgear.com/support/product/ms60/
https://www.netgear.com/support/product/ms70/
https://www.netgear.com/support/product/ms80/
https://www.netgear.com/support/product/rax15/
https://www.netgear.com/support/product/rax20/
https://www.netgear.com/support/product/rax200/
https://www.netgear.com/support/product/rax35v2/
https://www.netgear.com/support/product/rax38v2/
https://www.netgear.com/support/product/rax40v2/
https://www.netgear.com/support/product/rax42/
https://www.netgear.com/support/product/rax43/
https://www.netgear.com/support/product/rax45/
https://www.netgear.com/support/product/rax48/
https://www.netgear.com/support/product/rax50/
https://www.netgear.com/support/product/rax50s/
https://www.netgear.com/support/product/rax75/
https://www.netgear.com/support/product/rax80/
https://www.netgear.com/support/product/raxe450/
https://www.netgear.com/support/product/raxe500/
https://www.netgear.com/support/product/rbr750/
https://www.netgear.com/support/product/rbr840/
https://www.netgear.com/support/product/rbr850/
https://www.netgear.com/support/product/rbre960/
https://www.netgear.com/support/product/rbs750/
https://www.netgear.com/support/product/rbs840/
https://www.netgear.com/support/product/rbs850/
https://www.netgear.com/support/product/rbse960/
https://www.netgear.com/support/product/rs700/
https://www.netgear.com/support/product/xr1000/


 

AFFECTED (from MITRE)


Vendor Product Versions
NETGEAR CBR750
  • < v4.6.14.4 [affected]
NETGEAR EX6120
  • ≤ 1.0.0.72 [affected]
NETGEAR EX6130
  • ≤ 1.0.0.54 [affected]
NETGEAR MR60
  • < V1.1.7.128 [affected]
NETGEAR MR70
  • < V1.0.3.28 [affected]
NETGEAR MR80
  • < V1.1.7.6 [affected]
NETGEAR MS60
  • < V1.1.7.128 [affected]
NETGEAR MS70
  • < V1.0.3.28 [affected]
NETGEAR MS80
  • < V1.1.7.6 [affected]
NETGEAR RAX15
  • ≤ 1.0.18.144 [affected]
NETGEAR RAX20
  • ≤ 1.0.18.144 [affected]
NETGEAR RAX200
  • ≤ 1.0.11.148 [affected]
NETGEAR RAX35v2
  • < V1.0.11.112 [affected]
NETGEAR RAX38v2
  • < V1.0.11.112 [affected]
NETGEAR RAX40v2
  • < V1.0.11.112 [affected]
NETGEAR RAX42
  • < V1.0.11.112 [affected]
NETGEAR RAX43
  • < V1.0.11.112 [affected]
NETGEAR RAX45
  • < V1.0.11.112 [affected]
NETGEAR RAX48
  • < V1.0.11.112 [affected]
NETGEAR RAX50
  • < V1.0.11.112 [affected]
NETGEAR RAX50S
  • < V1.0.11.112 [affected]
NETGEAR RAX75
  • ≤ 1.0.11.148 [affected]
NETGEAR RAX80
  • ≤ 1.0.11.148 [affected]
NETGEAR RAXE450
  • < V1.0.10.86 [affected]
NETGEAR RAXE500
  • < V1.0.10.86 [affected]
NETGEAR RBR750
  • < V4.6.14.3 [affected]
NETGEAR RBR840
  • < V4.6.14.3 [affected]
NETGEAR RBR850
  • < V4.6.14.3 [affected]
NETGEAR RBRE960
  • < V6.3.7.5 [affected]
NETGEAR RBS750
  • < V4.6.14.3 [affected]
NETGEAR RBS840
  • < V4.6.14.3 [affected]
NETGEAR RBS850
  • < V4.6.14.3 [affected]
NETGEAR RBSE960
  • < V6.3.7.5 [affected]
NETGEAR RS700
  • < V1.0.7.66 [affected]
NETGEAR XR1000
  • < v1.0.0.68 [affected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
13 Subverting Environment Variable Values
Very High
146 XML Schema Poisoning
High
176 Configuration/Environment Manipulation
Medium
203 Manipulate Registry Information
Medium
270 Modification of Registry Run Keys
Medium
271 Schema Poisoning
High
579 Replace Winlogon Helper DLL
69 Target Programs with Elevated Privileges
Very High
76 Manipulating Web Input to File System Calls
Very High
77 Manipulating User-Controlled Variables
Very High


MITRE


Techniques

id description
T1112 Modify Registry
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Start Folder
T1547.004 Boot or Logon Autostart Execution: Winlogon helper DLL
T1547.014 Boot or Logon Autostart Execution: Active
T1562.003 Impair Defenses:Impair Command History Logging
T1574.006 Hijack Execution Flow:Dynamic Linker Hijacking
T1574.007 Hijack Execution Flow:Path Interception by PATH Environment Variable
T1647 Plist Modification
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Mitigations

id description
M1024 Ensure proper permissions are set for Registry hives to prevent users from modifying keys for system components that may lead to privilege escalation.
M1018 Limit the privileges of user accounts so that only authorized administrators can perform Winlogon helper changes.
M1028 Make sure that the <code>HISTCONTROL</code> environment variable is set to “ignoredups” instead of “ignoreboth” or “ignorespace”.
M1028 When System Integrity Protection (SIP) is enabled in macOS, the aforementioned environment variables are ignored when executing protected binaries. Third-party applications can also leverage Apple’s Hardened Runtime, ensuring these environment variables are subject to imposed restrictions. Admins can add restrictions to applications by setting the setuid and/or setgid bits, use entitlements, or have a __RESTRICT segment in the Mach-O binary.
M1022 Ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory <code>C:</code> and system directories, such as <code>C:Windows</code>, to reduce places where malicious files could be placed for execution. Require that all executables be placed in write-protected directories.
M1013 Ensure applications are using Apple's developer guidance which enables hardened runtime.
© 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation.