CVE-2026-9210

MEDIUM
4.5CVSS v3
CVSS v2
0.22% EPSS (exploit probability)
CWE-20CWE

Description

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

CVSS v3 vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Affected routers (2)

VendorModelMatched viaAffected versionsFixed inPatch Status
Netgear Netgear Nighthawk R6700v3 versionEndExcluding=1.0.4.128 1.0.4.128 Patched
Netgear Netgear Nighthawk R7000 versionEndExcluding=1.0.11.216 1.3.3.152 Patched

External references