4.3

CVE-2026-11738

Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNETGEAR
Produkt R7000
Default Statusaffected
Version 0
Version < *
Status affected
HerstellerNETGEAR
Produkt RAXE500
Default Statusunaffected
Version 0
Version < V1.2.14.114
Status affected
HerstellerNETGEAR
Produkt RS700
Default Statusunaffected
Version 0
Version < V1.0.7.66
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NETGEAR 4.3 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.netgear.com/support/product/r7000/
https://www.netgear.com/support/product/raxe500/
https://www.netgear.com/support/product/rs700/
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory