CVE-2026-9212
Last modified
CVE-2026-9212 is a high-severity vulnerability rated 8/10 on the CVSS scale. Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Lbr1020 Firmware | < 2.6.4.60 |
| Netgear | Lbr20 Firmware | < 2.7.6.8 |
| Netgear | R6700ax Firmware | All versions |
| Netgear | R7800 Firmware | < 1.0.4.96 |
| Netgear | R9000 Firmware | < 1.0.6.46 |
| Netgear | Rax10 Firmware | < 1.0.5.50 |
| Netgear | Rax120 Firmware | < 1.2.10.56 |
| Netgear | Rax36s Firmware | < 1.0.5.50 |
| Netgear | Rax70 Firmware | < 1.0.19.172 |
| Netgear | Rax78 Firmware | < 1.0.19.172 |
| Netgear | Rbr10 Firmware | All versions |
| Netgear | Rbr20 Firmware | All versions |
| Netgear | Rbr350 Firmware | < 4.4.2.1 |
| Netgear | Rbr40 Firmware | All versions |
| Netgear | Rbr50 Firmware | All versions |
| Netgear | Rbs10 Firmware | All versions |
| Netgear | Rbs20 Firmware | All versions |
| Netgear | Rbs350 Firmware | < 4.4.2.1 |
| Netgear | Rbs40 Firmware | All versions |
| Netgear | Rbs50 Firmware | All versions |
| Netgear | Xr450 Firmware | < 2.3.3.136 |
| Netgear | Xr500 Firmware | < 2.3.3.136 |
References
- https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-AdvisoryPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-9212?
How severe is CVE-2026-9212?
How do I fix CVE-2026-9212?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9204GitLab has remediated an issue in GitLab CE/EE affecting all…6.5
- CVE-2026-9205IBM Langflow OSS contains a weak cryptographic key derivatio…9.8
- CVE-2026-9207Tanium addressed an unauthorized code execution vulnerabilit…8.8
- CVE-2026-9208Tanium addressed an unauthorized code execution vulnerabilit…8.8
- CVE-2026-9210Insufficient input validation vulnerability in the listed NE…4.5
- CVE-2026-9211An unauthenticated user on the local network can gain contro…8.8
- CVE-2026-9213A vulnerability in the affected NETGEAR gaming routers allow…8.1
- CVE-2026-9214Insufficient input validation vulnerability in the NETGEAR R…4.3
- CVE-2026-9219Setracker2 Android Companion App com.tgelec.setracker versio…8.3
- CVE-2026-9220Setracker2 Android Companion App com.tgelec.setracker versio…8.7
- CVE-2026-9221The Setracker2 Android Companion App (com.tgelec.setracker) …8.7
- CVE-2026-9222Setracker2 Android Companion App com.tgelec.setracker versio…9.2
Are you affected by CVE-2026-9212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
