CVE-2026-9216
Last modified
CVE-2026-9216 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Rax30 Firmware | < 1.0.9.92 |
| Netgear | Rax35 Firmware | < 1.0.10.72 |
| Netgear | Rax38 Firmware | < 1.0.6.106 |
| Netgear | Rax40 Firmware | < 1.0.6.106 |
| Netgear | Raxe300 Firmware | < 1.0.10.72 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-9216?
How severe is CVE-2026-9216?
How do I fix CVE-2026-9216?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92138The OAuth authorization endpoint in Jenkins Bitbucket Server…4.2
- CVE-2026-92139Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and ear…6.5
- CVE-2026-9214Insufficient input validation vulnerability in the NETGEAR R…4.5
- CVE-2026-92140Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not…6.8
- CVE-2026-92141Jenkins Keycloak Authentication Plugin 2.4.1 and earlier doe…4.3
- CVE-2026-9215A cross site request forgery (CSRF) vulnerability in the lis…6.7
- CVE-2026-92176pdfforge PDF Architect App Object Out-Of-Bounds Read Remote …7.8
- CVE-2026-92177pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write …7.8
- CVE-2026-92178pdfforge PDF Architect PDF File Parsing Memory Corruption Re…7.8
- CVE-2026-92179pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write …7.8
- CVE-2026-92180pdfforge PDF Architect activation-service Update Service Unc…7.8
- CVE-2026-92184A security flaw has been discovered in ag-ui-protocol ag-ui …6.3
Are you affected by CVE-2026-9216?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
