CVE-2026-9212
5.6
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: a2826606-91e7-4eb6-899e-8484bd4575d5 (Secondary)
Description
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
Affected (22)
Products: Netgear: Lbr1020 Firmware, Lbr20 Firmware, R6700ax Firmware, R7800 Firmware, R9000 Firmware, Rax10 Firmware, Rax120 Firmware, Rax36s Firmware, Rax70 Firmware, Rax78 Firmware, Rbr10 Firmware, Rbr20 Firmware, Rbr350 Firmware, Rbr40 Firmware, Rbr50 Firmware, Rbs10 Firmware, Rbs20 Firmware, Rbs350 Firmware, Rbs40 Firmware, Rbs50 Firmware, Xr450 Firmware, Xr500 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.4.60 |
| Running on/with | Platform Versions |
|---|---|
Netgear Lbr1020 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.6.8 |
| Running on/with | Platform Versions |
|---|---|
Netgear Lbr20 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear R6700ax | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.4.96 |
| Running on/with | Platform Versions |
|---|---|
Netgear R7800 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6.46 |
| Running on/with | Platform Versions |
|---|---|
Netgear R9000 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.5.50 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rax10 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.10.56 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rax120 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.5.50 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rax36s | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.19.172 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rax70 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.19.172 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rax78 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbr10 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbr20 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2.1 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbr350 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbr40 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbr50 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbs10 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbs20 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2.1 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbs350 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbs40 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbs50 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.3.136 |
| Running on/with | Platform Versions |
|---|---|
Netgear Xr450 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.3.136 |
| Running on/with | Platform Versions |
|---|---|
Netgear Xr500 | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-306
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
References (24)
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchVendor Advisory
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
Product
Timeline
No history available yet.