CVE-2026-11739
Command injection vulnerability in some NETGEAR Nighthawk devices
Record summary
CVE-2026-11739 has a selected CVSS score of 4.9 (medium).
Description
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
Showing 12 of 27| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before V1.1.8.142 | affected |
Default status: unaffected | CVE List | Before V1.0.4.48 | affected |
Default status: unaffected | CVE List | Before V1.0.2.46 | affected |
Default status: unaffected | CVE List | Before V1.1.8.142 | affected |
Default status: unaffected | CVE List | Before V1.0.4.48 | affected |
Default status: unaffected | CVE List | Before V1.0.2.46 | affected |
Default status: unaffected | CVE List | Before V1.0.17.142 | affected |
RAX200Browse NETGEAR / RAX200Default status: unaffected | CVE List | Before V1.0.11.148 | affected |
Default status: unaffected | CVE List | Before V1.0.17.142 | affected |
RAX35v2Browse NETGEAR / RAX35v2Default status: unaffected | CVE List | Before V1.0.17.142 | affected |
Default status: unaffected | CVE List | Before V1.1.6.36 | affected |
RAX41v2Browse NETGEAR / RAX41v2Default status: unaffected | CVE List | Before V1.1.6.36 | affected |