CVE-2026-9212
HIGHCVSS 8/10EPSS 0.27%
Last modified
CVE-2026-9212 is a high-severity vulnerability rated 8/10 on the CVSS scale. Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Lbr1020 Firmware | < 2.6.4.60 |
| Netgear | Lbr20 Firmware | < 2.7.6.8 |
| Netgear | R6700ax Firmware | All versions |
| Netgear | R7800 Firmware | < 1.0.4.96 |
| Netgear | R9000 Firmware | < 1.0.6.46 |
| Netgear | Rax10 Firmware | < 1.0.5.50 |
| Netgear | Rax120 Firmware | < 1.2.10.56 |
| Netgear | Rax36s Firmware | < 1.0.5.50 |
| Netgear | Rax70 Firmware | < 1.0.19.172 |
| Netgear | Rax78 Firmware | < 1.0.19.172 |
| Netgear | Rbr10 Firmware | All versions |
| Netgear | Rbr20 Firmware | All versions |
| Netgear | Rbr350 Firmware | < 4.4.2.1 |
| Netgear | Rbr40 Firmware | All versions |
| Netgear | Rbr50 Firmware | All versions |
| Netgear | Rbs10 Firmware | All versions |
| Netgear | Rbs20 Firmware | All versions |
| Netgear | Rbs350 Firmware | < 4.4.2.1 |
| Netgear | Rbs40 Firmware | All versions |
| Netgear | Rbs50 Firmware | All versions |
| Netgear | Xr450 Firmware | < 2.3.3.136 |
| Netgear | Xr500 Firmware | < 2.3.3.136 |
References
- https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-AdvisoryPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-9212?
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
How severe is CVE-2026-9212?
CVE-2026-9212 has a CVSS score of 8/10 (HIGH severity). The EPSS model estimates a 0.27% probability of exploitation in the next 30 days.
How do I fix CVE-2026-9212?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92091A flaw was found in jwcrypto. The JWK.import_key() function …5.9
- CVE-2026-92099The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does…6.5
- CVE-2026-9210Insufficient input validation vulnerability in the listed NE…4.5
- CVE-2026-92106Improper Neutralization of Input During Web Page Generation …2.3
- CVE-2026-9211An unauthenticated user on the local network can gain contro…8.8
- CVE-2026-92114A vulnerability was identified in a2ui-project a2ui up to 0.…5.3
- CVE-2026-92122Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8.8
- CVE-2026-92123Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8.8
- CVE-2026-92124Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8.8
- CVE-2026-92125Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8.8
- CVE-2026-92126Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8.5
- CVE-2026-92127Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and ear…8
Are you affected by CVE-2026-9212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
