4.3

CVE-2026-11737

Some NETGEAR Nighthawk devices allow administrators to tamper with the device

Insufficient input validation vulnerability in the listed 
NETGEAR models allows authenticated administrators connected to the 
local network to make unauthorized modification to the device software and 
functionality.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNETGEAR
Produkt RAX20
Default Statusunaffected
Version 0
Version < V1.0.18.144
Status affected
HerstellerNETGEAR
Produkt RAX41
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX41v2
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX42
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX42v2
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX43
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX43v2
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX45
Default Statusunaffected
Version 0
Version < V1.0.17.142
Status affected
HerstellerNETGEAR
Produkt RAX49S
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX50
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX50v2
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX54S
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
HerstellerNETGEAR
Produkt RAX54Sv2
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.161
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NETGEAR 4.3 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.netgear.com/support/product/rax20/
https://www.netgear.com/support/product/rax41/
https://www.netgear.com/support/product/rax41v2/
https://www.netgear.com/support/product/rax42v2/
https://www.netgear.com/support/product/rax42/
https://www.netgear.com/support/product/rax43/
https://www.netgear.com/support/product/rax43v2/
https://www.netgear.com/support/product/rax45/
https://www.netgear.com/support/product/rax50/
https://www.netgear.com/support/product/rax50v2/
https://www.netgear.com/support/product/rax49s/
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory