CVE-2026-9212

Published Jun 9, 2026

Last updated a month ago

Overview

Description
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
Source
a2826606-91e7-4eb6-899e-8484bd4575d5
NVD status
Analyzed
Products
lbr1020_firmware, lbr20_firmware, r6700ax_firmware, r7800_firmware, r9000_firmware, rax10_firmware, rax120_firmware, rax36s_firmware, rax70_firmware, rax78_firmware, rbr10_firmware, rbr20_firmware, rbr350_firmware, rbr40_firmware, rbr50_firmware, rbs10_firmware, rbs20_firmware, rbs350_firmware, rbs40_firmware, rbs50_firmware, xr450_firmware, xr500_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.6
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
8
Impact score
5.9
Exploitability score
2.1
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

a2826606-91e7-4eb6-899e-8484bd4575d5
CWE-20

Social media

Hype score
Not currently trending

Configurations