CVE-2026-9212

HIGH

Insufficient authentication and input validation in certain NETGEAR products

Title source: cna
STIX 2.1

Description

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

References (24)

Core 24
Core References

Scores

CVSS v3 8.0
EPSS 0.0027
EPSS Percentile 19.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-306
Status published
Products (48)
NETGEAR/LBR1020 < V2.6.4.60
netgear/lbr1020_firmware < 2.6.4.60
NETGEAR/LBR20 < V2.7.6.8
netgear/lbr20_firmware < 2.7.6.8
NETGEAR/R6700AX
NETGEAR/R6700AX < 1.0.20.174
netgear/r6700ax_firmware
NETGEAR/R7800 < V1.0.4.96
netgear/r7800_firmware < 1.0.4.96
NETGEAR/R9000 < V1.0.6.46
... and 38 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026