CVE-2026-9212
HIGH8.0CVSS v3
—CVSS v2
0.27%
EPSS (exploit probability)
CWE-20CWE
Description
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
CVSS v3 vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected routers (3)
| Vendor | Model | Matched via | Affected versions | Fixed in | Patch Status |
|---|---|---|---|---|---|
| Netgear | Netgear Nighthawk R7800 | — |
versionEndExcluding=1.0.4.96 | 1.0.4.96 | Patched |
| Netgear | Netgear Nighthawk RAX120 | — |
versionEndExcluding=1.2.10.56 | 1.2.10.56 | Patched |
| Netgear | Netgear Orbi RBR50 | — |
— | — | Likely Patched |