CVE-2026-9211

HIGH

Certain NETGEAR routers allow unauthenticated users to gain control of the router

Title source: cna
STIX 2.1

Description

An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.

Scores

CVSS v3 8.8
EPSS 0.0024
EPSS Percentile 14.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (8)
NETGEAR/CAX30 < V2.2.1.4
netgear/cax30_firmware < 2.2.1.4
NETGEAR/RAX30 < V1.0.10.94
netgear/rax30_firmware < 1.0.10.94
NETGEAR/RAX5 < V1.0.5.34
netgear/rax5_firmware < 1.0.5.34
NETGEAR/RAXE300 < V1.0.10.72
netgear/raxe300_firmware < 1.0.10.72
Published Jun 09, 2026
Tracked Since Jun 09, 2026