CVE-2026-0408: NETGEAR EX2800 Firmware

High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.

A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.

Affected products

  • NETGEAR EX2800 Firmware: before 1.0.1.82 (fixed in 1.0.1.82)
  • NETGEAR EX3110 Firmware: before 1.0.1.82 (fixed in 1.0.1.82)
  • NETGEAR EX5000 Firmware: before 1.0.1.82 (fixed in 1.0.1.82)
  • NETGEAR EX6110 Firmware: before 1.0.1.82 (fixed in 1.0.1.82)

Published 2026-01-13. Last modified 2026-06-17.