NETGEAR Vulnerabilities and Affected Products
Vulnerabilities associated with RAXE500.
Products
Clear product- r7000p_firmware27 vulnerabilities
- r8500_firmware25 vulnerabilities
- xr300_firmware25 vulnerabilities
- ProSAFE Network Management System23 vulnerabilities
- RAX3022 vulnerabilities
- r6400_firmware17 vulnerabilities
- SRX530817 vulnerabilities
- prosafe_network_management_system16 vulnerabilities
- RAX4315 vulnerabilities
- rax30_firmware14 vulnerabilities
- RAX5013 vulnerabilities
- RAXE50013 vulnerabilities
- R670012 vulnerabilities
- XR100012 vulnerabilities
- RAX4211 vulnerabilities
- RAX4511 vulnerabilities
- Multiple Routers10 vulnerabilities
- RAX4110 vulnerabilities
- EX62009 vulnerabilities
- JWNR2000v29 vulnerabilities
- R6700v39 vulnerabilities
- R70009 vulnerabilities
- R78009 vulnerabilities
- RAX209 vulnerabilities
- RAX54Sv29 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routersA stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. CWE-20Aug 11, 2026 | CVSS1.9v4.0 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk modelsA stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. CWE-121Aug 11, 2026 | CVSS1.9v4.0 | EPSS0.313% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-11738MEDIUM | Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. CWE-20Aug 11, 2026 | CVSS4.3v4.0 | EPSS0.197% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11739MEDIUM | Command injection vulnerability in some NETGEAR Nighthawk devicesA command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device. CWE-78Aug 11, 2026 | CVSS4.9v4.0 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62656MEDIUM | Post-authenticated command injection vulnerability found in certain NETGEAR RAX modelsA security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation. CWE-20Jul 14, 2026 | CVSS5.4v4.0 | EPSS0.163% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62657MEDIUM | Certificate validation vulnerability in NETGEAR Gaming Router and certain Nighthawk modelsA security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device. CWE-599Jul 14, 2026 | CVSS4.9v4.0 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0418MEDIUM | Certain NETGEAR devices allow administrators to tamper with systemInsufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. | CVSS4.3v4.0 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0417MEDIUM | Insufficient input validation in certain NETGEAR routersInsufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. CWE-20Jun 9, 2026 | CVSS4.3v4.0 | EPSS0.229% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9210MEDIUM | Certain NETGEAR routers allow authenticated administrators to gain unintended control of the routerInsufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. CWE-20Jun 9, 2026 | CVSS4.9v4.0 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0416MEDIUM | Improper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionalityAn insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality. CWE-20Jun 9, 2026 | CVSS4.3v4.0 | EPSS0.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9213MEDIUM | Insufficient input validation in certain NETGEAR routersA vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device. CWE-20Jun 9, 2026 | CVSS6.9v4.0 | EPSS0.397% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Insufficient input validation in certain NETGEAR routersAuthenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality. CWE-20Jun 9, 2026 | CVSS1.9v4.0 | EPSS0.219% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-12946MEDIUM | Improper input validation in NETGEAR Nighthawk routersA vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RA… CWE-20Dec 9, 2025 | CVSS4.4v4.0 | EPSS0.286% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |