Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting product's confidentiality or change certain configurations.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

NETGEAR strongly recommends that you install the latest firmware as soon as possible. Issue fixed in: ProductFixed VersionLBR1020* V2.6.4.60 https://www.netgear.com/support/product/lbr1020/ LBR20 V2.7.6.8 https://www.netgear.com/support/product/lbr20/ R6700AX*EOSR7800* V1.0.4.96 https://www.netgear.com/support/product/r7800/ R9000* V1.0.6.46 https://www.netgear.com/support/product/r9000/ RAX10 V1.0.5.50 https://www.netgear.com/support/product/rax10/ RAX10v2V1.0.5.50RAX120 V1.2.10.56 https://www.netgear.com/support/product/rax120/ RAX120v1*V1.2.10.56RAX120v2 V1.2.10.56 https://www.netgear.com/support/product/rax120v2/ RAX36S V1.0.5.50 https://www.netgear.com/support/product/rax36s/ RAX70 V1.0.19.172 https://www.netgear.com/support/product/rax70/ RAX78 V1.0.19.172 https://www.netgear.com/support/product/rax78/ RBR10*EOSRBR20*EOSRBR350 V4.4.2.1 https://www.netgear.com/support/product/rbr350/ RBR40*EOSRBR50*EOSRBS10*EOSRBS20*EOSRBS350 V4.4.2.1 https://www.netgear.com/support/product/rbs350/ RBS40*EOSRBS50*EOSXR450* V2.3.3.136 https://www.netgear.com/support/product/xr450/ XR500* v2.3.3.136 https://www.netgear.com/support/product/xr500/ * Model has reached its End-of-Support (EOS) phase and no future security updates are planned. NETGEAR strongly recommends that you retire this device and upgrade to a newer NETGEAR product for continued security support.


Workaround

No workaround given by the vendor.

History

Tue, 09 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Description Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting product's confidentiality or change certain configurations.
Title Insufficient authentication and input validation in certain NETGEAR products
Weaknesses CWE-20
CWE-306
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-06-09T17:14:19.123Z

Reserved: 2026-05-21T17:29:04.787Z

Link: CVE-2026-9212

cve-icon Vulnrichment

Updated: 2026-06-09T17:14:10.889Z

cve-icon NVD

Status : Received

Published: 2026-06-09T17:17:51.517

Modified: 2026-06-09T17:17:51.517

Link: CVE-2026-9212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T17:45:10Z

Weaknesses