CVE-2026-11737

Published Aug 11, 2026

Last updated 8 days ago

Overview

Description
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
Source
a2826606-91e7-4eb6-899e-8484bd4575d5
NVD status
Analyzed
Products
rax20_firmware, rax41_firmware, rax41v2_firmware, rax42_firmware, rax42v2_firmware, rax43_firmware, rax43v2_firmware, rax45_firmware, rax49s_firmware, rax50_firmware, rax50v2_firmware, rax54s_firmware, rax54sv2_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
4.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
4.5
Impact score
3.6
Exploitability score
0.9
Vector string
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

a2826606-91e7-4eb6-899e-8484bd4575d5
CWE-20

Social media

Hype score
Not currently trending

Configurations