CVE-2026-9212

HIGH
8.0CVSS v3
CVSS v2
0.27% EPSS (exploit probability)
CWE-20CWE

Description

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

CVSS v3 vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected routers (3)

VendorModelMatched viaAffected versionsFixed inPatch Status
Netgear Netgear Nighthawk R7800 versionEndExcluding=1.0.4.96 1.0.4.96 Patched
Netgear Netgear Nighthawk RAX120 versionEndExcluding=1.2.10.56 1.2.10.56 Patched
Netgear Netgear Orbi RBR50 Likely Patched

External references