CVE-2026-9212
HIGHInsufficient authentication and input validation in certain NETGEAR products
Title source: cnaDescription
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
References (24)
Core 24
Core References
Patch product
patch
https://www.netgear.com/support/product/lbr20/
Patch product
patch
https://www.netgear.com/support/product/lbr1020/
Patch product
patch
https://www.netgear.com/support/product/rax70/
Patch product
patch
https://www.netgear.com/support/product/rbr10/
Patch product
patch
https://www.netgear.com/support/product/rbr350/
Patch product
patch
https://www.netgear.com/support/product/rbr40/
Patch product
patch
https://www.netgear.com/support/product/rbr50/
Patch product
patch
https://www.netgear.com/support/product/rbs10/
Patch product
patch
https://www.netgear.com/support/product/rbs20/
Patch product
patch
https://www.netgear.com/support/product/rax36s/
Patch product
patch
https://www.netgear.com/support/product/rbr20/
Patch product
patch
https://www.netgear.com/support/product/rbs50/
Patch product
patch
https://www.netgear.com/support/product/rbs350/
Patch product
patch
https://www.netgear.com/support/product/xr500/
Patch product
patch
https://www.netgear.com/support/product/rbs40/
Patch product
patch
https://www.netgear.com/support/product/r6700ax/
Patch product
patch
https://www.netgear.com/support/product/r9000/
Patch product
patch
https://www.netgear.com/support/product/r7800/
Patch product
patch
https://www.netgear.com/support/product/rax10/
Patch product
patch
https://www.netgear.com/support/product/rax120/
Patch product
patch
https://www.netgear.com/support/product/rax78/
Patch product
patch
https://www.netgear.com/support/product/rax120v2/
Patch product
patch
https://www.netgear.com/support/product/xr450/
Vendor Advisory vendor-advisory
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
Scores
CVSS v3
8.0
EPSS
0.0027
EPSS Percentile
19.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
CWE-306
Status
published
Products (48)
NETGEAR/LBR1020
< V2.6.4.60
netgear/lbr1020_firmware
< 2.6.4.60
NETGEAR/LBR20
< V2.7.6.8
netgear/lbr20_firmware
< 2.7.6.8
NETGEAR/R6700AX
NETGEAR/R6700AX
< 1.0.20.174
netgear/r6700ax_firmware
NETGEAR/R7800
< V1.0.4.96
netgear/r7800_firmware
< 1.0.4.96
NETGEAR/R9000
< V1.0.6.46
... and 38 more
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026