CVE-2026-9212

MEDIUMCVSS 5.6/10EPSS 0.27%

Last modified

CVE-2026-9212 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.

Description

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

Metrics

CVSS 3.1
8/10

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS 4.0
5.6/10

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.27%

18.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NetgearLbr1020 Firmware< 2.6.4.60
NetgearLbr20 Firmware< 2.7.6.8
NetgearR6700ax FirmwareAll versions
NetgearR7800 Firmware< 1.0.4.96
NetgearR9000 Firmware< 1.0.6.46
NetgearRax10 Firmware< 1.0.5.50
NetgearRax120 Firmware< 1.2.10.56
NetgearRax36s Firmware< 1.0.5.50
NetgearRax70 Firmware< 1.0.19.172
NetgearRax78 Firmware< 1.0.19.172
NetgearRbr10 FirmwareAll versions
NetgearRbr20 FirmwareAll versions
NetgearRbr350 Firmware< 4.4.2.1
NetgearRbr40 FirmwareAll versions
NetgearRbr50 FirmwareAll versions
NetgearRbs10 FirmwareAll versions
NetgearRbs20 FirmwareAll versions
NetgearRbs350 Firmware< 4.4.2.1
NetgearRbs40 FirmwareAll versions
NetgearRbs50 FirmwareAll versions
NetgearXr450 Firmware< 2.3.3.136
NetgearXr500 Firmware< 2.3.3.136

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-9212?
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
How severe is CVE-2026-9212?
CVE-2026-9212 has a CVSS score of 5.6/10 (MEDIUM severity). The EPSS model estimates a 0.27% probability of exploitation in the next 30 days.
How do I fix CVE-2026-9212?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2026-9212?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST