CVE-2026-9212

MEDIUM EPSS 18.5%
Published Jun 9, 20262w ago · Modified Jun 18, 20261w ago
5.6 CVSS 4.0
Medium
Find Similar
Published Jun 9, 2026 2w ago
Last Modified Jun 18, 2026 1w ago

Description

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

CVSS Details

Base Score
5.6
Exploitability
Impact
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Adjacent
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
18.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 2

CWE-20 Improper Input Validation Validation
CWE-306 Missing Authentication for Critical Function Authentication

Affected Products 46

VendorProductVersionRange
netgearlbr1020_firmware* <2.6.4.60
netgearlbr1020*any
netgearlbr20_firmware* <2.7.6.8
netgearlbr20*any
netgearr6700ax_firmware*any
netgearr6700ax*any
netgearr7800_firmware* <1.0.4.96
netgearr7800*any
netgearr9000_firmware* <1.0.6.46
netgearr9000*any
netgearrax10_firmware* <1.0.5.50
netgearrax10*any
netgearrax120_firmware* <1.2.10.56
netgearrax120*any
netgearrax1201.0any
netgearrax1202.0any
netgearrax36s_firmware* <1.0.5.50
netgearrax36s*any
netgearrax70_firmware* <1.0.19.172
netgearrax70*any
netgearrax78_firmware* <1.0.19.172
netgearrax78*any
netgearrbr10_firmware*any
netgearrbr10*any
netgearrbr20_firmware*any
netgearrbr20*any
netgearrbr350_firmware* <4.4.2.1
netgearrbr350*any
netgearrbr40_firmware*any
netgearrbr40*any
netgearrbr50_firmware*any
netgearrbr50*any
netgearrbs10_firmware*any
netgearrbs10*any
netgearrbs20_firmware*any
netgearrbs20*any
netgearrbs350_firmware* <4.4.2.1
netgearrbs350*any
netgearrbs40_firmware*any
netgearrbs40*any
netgearrbs50_firmware*any
netgearrbs50*any
netgearxr450_firmware* <2.3.3.136
netgearxr450*any
netgearxr500_firmware* <2.3.3.136
netgearxr500*any

References 24

  • kb.netgear.com https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
    PatchVendor Advisory
  • netgear.com https://www.netgear.com/support/product/lbr1020/
    Product
  • netgear.com https://www.netgear.com/support/product/lbr20/
    Product
  • netgear.com https://www.netgear.com/support/product/r6700ax/
    Product
  • netgear.com https://www.netgear.com/support/product/r7800/
    Product
  • netgear.com https://www.netgear.com/support/product/r9000/
    Product
  • netgear.com https://www.netgear.com/support/product/rax10/
    Product
  • netgear.com https://www.netgear.com/support/product/rax120/
    Product
  • netgear.com https://www.netgear.com/support/product/rax120v2/
    Product
  • netgear.com https://www.netgear.com/support/product/rax36s/
    Product
  • netgear.com https://www.netgear.com/support/product/rax70/
    Product
  • netgear.com https://www.netgear.com/support/product/rax78/
    Product
  • netgear.com https://www.netgear.com/support/product/rbr10/
    Product
  • netgear.com https://www.netgear.com/support/product/rbr20/
    Product
  • netgear.com https://www.netgear.com/support/product/rbr350/
    Product
  • netgear.com https://www.netgear.com/support/product/rbr40/
    Product
  • netgear.com https://www.netgear.com/support/product/rbr50/
    Product
  • netgear.com https://www.netgear.com/support/product/rbs10/
    Product
  • netgear.com https://www.netgear.com/support/product/rbs20/
    Product
  • netgear.com https://www.netgear.com/support/product/rbs350/
    Product
  • netgear.com https://www.netgear.com/support/product/rbs40/
    Product
  • netgear.com https://www.netgear.com/support/product/rbs50/
    Product
  • netgear.com https://www.netgear.com/support/product/xr450/
    Product
  • netgear.com https://www.netgear.com/support/product/xr500/
    Product

Remediation

  • kb.netgear.com https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
    PatchVendor Advisory