4.9
CVE-2026-11736
- EPSS 0.31%
- Veröffentlicht 11.08.2026 15:06:19
- Zuletzt bearbeitet 09.09.2026 02:58:40
- Erkennungen
Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Rax20 Firmware Version -
Netgear ≫ Rax35v2 Firmware Version < 1.0.16.132
Netgear ≫ Rax41 Firmware Version -
Netgear ≫ Rax41v2 Firmware Version < 1.1.4.28
Netgear ≫ Rax42 Firmware Version -
Netgear ≫ Rax42v2 Firmware Version < 1.1.4.28
Netgear ≫ Rax43 Firmware Version < 1.0.16.132
Netgear ≫ Rax43v2 Firmware Version < 1.1.4.28
Netgear ≫ Rax45 Firmware Version -
Netgear ≫ Rax49s Firmware Version < 1.1.4.28
Netgear ≫ Rax50 Firmware Version < 1.0.16.132
Netgear ≫ Rax50s Firmware Version -
Netgear ≫ Rax50v2 Firmware Version < 1.1.4.28
Netgear ≫ Rax54sv2 Firmware Version < 1.1.4.28
Netgear ≫ Rax54v2 Firmware Version < 1.1.4.28
Netgear ≫ Raxe450 Firmware Version -
Netgear ≫ Raxe500 Firmware Version < 1.2.14.114
Netgear ≫ Xr1000 Firmware Version < 1.1.0.22
Netgear ≫ Xr1000v2 Firmware Version < 1.1.0.22
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.238 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
| NETGEAR | 1.9 | 0 | 0 |
CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://www.netgear.com/support/product/rax20/
https://www.netgear.com/support/product/rax35v2/
https://www.netgear.com/support/product/rax41/
https://www.netgear.com/support/product/rax41v2/
https://www.netgear.com/support/product/rax42v2/
https://www.netgear.com/support/product/rax42/
https://www.netgear.com/support/product/rax43/
https://www.netgear.com/support/product/rax43v2/
https://www.netgear.com/support/product/rax45/
https://www.netgear.com/support/product/raxe450/
https://www.netgear.com/support/product/rax50s/
https://www.netgear.com/support/product/rax50/
https://www.netgear.com/support/product/rax54sv2/
https://www.netgear.com/support/product/xr1000/
https://www.netgear.com/support/product/xr1000v2/
https://www.netgear.com/support/product/rax50v2/
https://www.netgear.com/support/product/rax49s/
https://www.netgear.com/support/product/raxe500/
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory