CVE-2026-11738

MEDIUMCVSS 4.4/10EPSS 0.20%

Last modified

CVE-2026-11738 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.

Description

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
NetgearBe9300 Firmware< 1.0.1.84
NetgearMr60 Firmware< 1.1.8.142
NetgearMs60 Firmware< 1.1.8.142
NetgearR6700ax Firmware< 1.0.18.164
NetgearRax10 Firmware< 1.0.5.50
NetgearRax120 Firmware< 1.2.10.56
NetgearRax120v2 Firmware< 1.2.10.56
NetgearRax20 Firmware< 1.0.17.142
NetgearRax28 Firmware< 1.0.14.108
NetgearRax29 Firmware< 1.0.14.108
NetgearRax30 Firmware< 1.0.14.108
NetgearRax36s Firmware< 1.0.5.50
NetgearRax43 Firmware< 1.0.17.142
NetgearRax45 Firmware< 1.0.17.142
NetgearRax50 Firmware< 1.0.17.142
NetgearRax70 Firmware< 1.0.19.172
NetgearRbr760 Firmware< 6.3.8.11
NetgearRbs760 Firmware< 6.3.8.11
NetgearRs100 Firmware< 1.0.1.80
NetgearRs200 Firmware< 1.0.1.90
NetgearRs280 Firmware< 1.0.1.90
NetgearRs300 Firmware< 1.0.1.90
NetgearRs500 Firmware< 1.0.1.90
NetgearRs600 Firmware< 1.0.1.90
NetgearRs70 Firmware< 1.0.1.80
NetgearRs90 Firmware< 1.0.1.80

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-11738?
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
How severe is CVE-2026-11738?
CVE-2026-11738 has a CVSS score of 4.4/10 (MEDIUM severity). The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2026-11738?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-11738?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST