CVE-2026-9211

MEDIUM

Certain NETGEAR routers allow unauthenticated users to gain control of the router

Title source: cna
STIX 2.1

Description

An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.

Scores

CVSS v4 5.2
EPSS 0.0021
EPSS Percentile 11.3%
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (4)
NETGEAR/CAX30 < V2.2.1.4
NETGEAR/RAX30 < V1.0.10.94
NETGEAR/RAX5 < V1.0.5.34
NETGEAR/RAXE300 < V1.0.10.72
Published Jun 09, 2026
Tracked Since Jun 09, 2026