kb.netgear.comVendor advisorypatch
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory CVE-2026-11738
MEDIUM
Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.
Record summary
CVE-2026-11738 has a selected CVSS score of 4.3 (medium).
Description
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Before * | affected |
RAXE500Browse NETGEAR / RAXE500Default status: unaffected | CVE List | Before V1.2.14.114 | affected |
Default status: unaffected | CVE List | Before V1.0.7.66 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-11738 netgear.comproductpatch
https://www.netgear.com/support/product/r7000 netgear.comproductpatch
https://www.netgear.com/support/product/raxe500 netgear.comproductpatch
https://www.netgear.com/support/product/rs700