VulnerabilityAnalyzed
CVE-2026-9212
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
MEDIUM 5.6EPSS 0.27%
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
- CVSS 4.0
- 5.6 MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-306
- Affected
- netgear/lbr1020 firmware · netgear/lbr20 firmware · netgear/r6700ax firmware · netgear/r7800 firmware · netgear/r9000 firmware · netgear/rax10 firmware · netgear/rax120 firmware · netgear/rax36s firmware · netgear/rax70 firmware · netgear/rax78 firmware · netgear/rbr10 firmware · netgear/rbr20 firmware · netgear/rbr350 firmware · netgear/rbr40 firmware · netgear/rbr50 firmware · netgear/rbs10 firmware · netgear/rbs20 firmware · netgear/rbs350 firmware · netgear/rbs40 firmware · netgear/rbs50 firmware · +2 more
- Source
- a2826606-91e7-4eb6-899e-8484bd4575d5
References
- https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-AdvisoryPatch, Vendor Advisory
- https://www.netgear.com/support/product/lbr1020/Product
- https://www.netgear.com/support/product/lbr20/Product
- https://www.netgear.com/support/product/r6700ax/Product
- https://www.netgear.com/support/product/r7800/Product
- https://www.netgear.com/support/product/r9000/Product
- https://www.netgear.com/support/product/rax10/Product
- https://www.netgear.com/support/product/rax120/Product
- https://www.netgear.com/support/product/rax120v2/Product
- https://www.netgear.com/support/product/rax36s/Product
- https://www.netgear.com/support/product/rax70/Product
- https://www.netgear.com/support/product/rax78/Product
- https://www.netgear.com/support/product/rbr10/Product
- https://www.netgear.com/support/product/rbr20/Product
- https://www.netgear.com/support/product/rbr350/Product
- https://www.netgear.com/support/product/rbr40/Product
- https://www.netgear.com/support/product/rbr50/Product
- https://www.netgear.com/support/product/rbs10/Product
- https://www.netgear.com/support/product/rbs20/Product
- https://www.netgear.com/support/product/rbs350/Product
- https://www.netgear.com/support/product/rbs40/Product
- https://www.netgear.com/support/product/rbs50/Product
- https://www.netgear.com/support/product/xr450/Product
- https://www.netgear.com/support/product/xr500/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.