CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routersA stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. CWE-20Aug 11, 2026 | CVSS1.9v4.0 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk modelsA stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. CWE-121Aug 11, 2026 | CVSS1.9v4.0 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-11739MEDIUM | Command injection vulnerability in some NETGEAR Nighthawk devicesA command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device. CWE-78Aug 11, 2026 | CVSS4.9v4.0 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Device administrator can interrupt the normal operation of some NETGEAR Nighthawk devices.A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. CWE-121Aug 11, 2026 | CVSS1.1v4.0 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Buffer overflow vulnerability in some NETGEAR Nighthawk routersA buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. CWE-121Aug 11, 2026 | CVSS1.1v4.0 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-11737MEDIUM | Some NETGEAR Nighthawk devices allow administrators to tamper with the deviceInsufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality. CWE-20Aug 11, 2026 | CVSS4.3v4.0 | EPSS0.247% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11814MEDIUM | Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routersA command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs. CWE-295Aug 11, 2026 | CVSS4.9v4.0 | EPSS0.825% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62658MEDIUM | Post-authentication Command Injection Vulnerability in certain Nighthawk RAX series modelsA security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router. CWE-20Jul 14, 2026 | CVSS4.7v4.0 | EPSS0.193% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0418MEDIUM | Certain NETGEAR devices allow administrators to tamper with systemInsufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. | CVSS4.3v4.0 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0417MEDIUM | Insufficient input validation in certain NETGEAR routersInsufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. CWE-20Jun 9, 2026 | CVSS4.3v4.0 | EPSS0.229% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9210MEDIUM | Certain NETGEAR routers allow authenticated administrators to gain unintended control of the routerInsufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. CWE-20Jun 9, 2026 | CVSS4.9v4.0 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Insufficient input validation in certain NETGEAR routersAuthenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality. CWE-20Jun 9, 2026 | CVSS1.9v4.0 | EPSS0.219% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-12946MEDIUM | Improper input validation in NETGEAR Nighthawk routersA vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RA… CWE-20Dec 9, 2025 | CVSS4.4v4.0 | EPSS0.286% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |