CVE-2026-9213

HIGH

Insufficient input validation in certain NETGEAR routers

Title source: cna
STIX 2.1

Description

A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.

Scores

CVSS v3 8.1
EPSS 0.0040
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (8)
NETGEAR/MR70 < V1.0.4.48
netgear/mr70_firmware < 1.0.4.48
NETGEAR/MS70 < V1.0.4.48
netgear/ms70_firmware < 1.0.4.48
NETGEAR/RAXE500 < V1.2.14.114
netgear/raxe500_firmware < 1.2.14.114
NETGEAR/XR1000 < V1.0.2.86
netgear/xr1000_firmware < 1.0.2.86
Published Jun 09, 2026
Tracked Since Jun 09, 2026