NETGEAR Vulnerabilities and Affected Products
Vulnerabilities associated with RAX20.
Products
Clear product- r7000p_firmware27 vulnerabilities
- r8500_firmware25 vulnerabilities
- xr300_firmware25 vulnerabilities
- ProSAFE Network Management System23 vulnerabilities
- RAX3022 vulnerabilities
- r6400_firmware17 vulnerabilities
- SRX530817 vulnerabilities
- prosafe_network_management_system16 vulnerabilities
- RAX4315 vulnerabilities
- rax30_firmware14 vulnerabilities
- RAX5013 vulnerabilities
- RAXE50013 vulnerabilities
- R670012 vulnerabilities
- XR100012 vulnerabilities
- RAX4211 vulnerabilities
- RAX4511 vulnerabilities
- Multiple Routers10 vulnerabilities
- RAX4110 vulnerabilities
- EX62009 vulnerabilities
- JWNR2000v29 vulnerabilities
- R6700v39 vulnerabilities
- R70009 vulnerabilities
- R78009 vulnerabilities
- RAX209 vulnerabilities
- RAX54Sv29 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routersA stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. CWE-20Aug 11, 2026 | CVSS1.9v4.0 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk modelsA stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. CWE-121Aug 11, 2026 | CVSS1.9v4.0 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-11739MEDIUM | Command injection vulnerability in some NETGEAR Nighthawk devicesA command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device. CWE-78Aug 11, 2026 | CVSS4.9v4.0 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11737MEDIUM | Some NETGEAR Nighthawk devices allow administrators to tamper with the deviceInsufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality. CWE-20Aug 11, 2026 | CVSS4.3v4.0 | EPSS0.247% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11814MEDIUM | Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routersA command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs. CWE-295Aug 11, 2026 | CVSS4.9v4.0 | EPSS0.825% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0418MEDIUM | Certain NETGEAR devices allow administrators to tamper with systemInsufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. | CVSS4.3v4.0 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0417MEDIUM | Insufficient input validation in certain NETGEAR routersInsufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. CWE-20Jun 9, 2026 | CVSS4.3v4.0 | EPSS0.229% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9210MEDIUM | Certain NETGEAR routers allow authenticated administrators to gain unintended control of the routerInsufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. CWE-20Jun 9, 2026 | CVSS4.9v4.0 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Insufficient input validation in certain NETGEAR routersAuthenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality. CWE-20Jun 9, 2026 | CVSS1.9v4.0 | EPSS0.219% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |