CVE-2026-9212
Last modified
CVE-2026-9212 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Lbr1020 Firmware | < 2.6.4.60 |
| Netgear | Lbr20 Firmware | < 2.7.6.8 |
| Netgear | R6700ax Firmware | All versions |
| Netgear | R7800 Firmware | < 1.0.4.96 |
| Netgear | R9000 Firmware | < 1.0.6.46 |
| Netgear | Rax10 Firmware | < 1.0.5.50 |
| Netgear | Rax120 Firmware | < 1.2.10.56 |
| Netgear | Rax36s Firmware | < 1.0.5.50 |
| Netgear | Rax70 Firmware | < 1.0.19.172 |
| Netgear | Rax78 Firmware | < 1.0.19.172 |
| Netgear | Rbr10 Firmware | All versions |
| Netgear | Rbr20 Firmware | All versions |
| Netgear | Rbr350 Firmware | < 4.4.2.1 |
| Netgear | Rbr40 Firmware | All versions |
| Netgear | Rbr50 Firmware | All versions |
| Netgear | Rbs10 Firmware | All versions |
| Netgear | Rbs20 Firmware | All versions |
| Netgear | Rbs350 Firmware | < 4.4.2.1 |
| Netgear | Rbs40 Firmware | All versions |
| Netgear | Rbs50 Firmware | All versions |
| Netgear | Xr450 Firmware | < 2.3.3.136 |
| Netgear | Xr500 Firmware | < 2.3.3.136 |
References
- https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-AdvisoryPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-9212?
How severe is CVE-2026-9212?
How do I fix CVE-2026-9212?
Are you affected by CVE-2026-9212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
