4.9
CVE-2026-11739
- EPSS 1.05%
- Veröffentlicht 11.08.2026 15:06:14
- Zuletzt bearbeitet 12.08.2026 08:17:16
- CVE-Watchlists
- Unerledigt
Command injection vulnerability in some NETGEAR Nighthawk devices
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNETGEAR
≫
Produkt
MR60
Default Statusunaffected
Version
0
Version <
V1.1.8.142
Status
affected
HerstellerNETGEAR
≫
Produkt
MR70
Default Statusunaffected
Version
0
Version <
V1.0.4.48
Status
affected
HerstellerNETGEAR
≫
Produkt
MR90
Default Statusunaffected
Version
0
Version <
V1.0.2.46
Status
affected
HerstellerNETGEAR
≫
Produkt
MS60
Default Statusunaffected
Version
0
Version <
V1.1.8.142
Status
affected
HerstellerNETGEAR
≫
Produkt
MS70
Default Statusunaffected
Version
0
Version <
V1.0.4.48
Status
affected
HerstellerNETGEAR
≫
Produkt
MS90
Default Statusunaffected
Version
0
Version <
V1.0.2.46
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX20
Default Statusunaffected
Version
0
Version <
V1.0.17.142
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX200
Default Statusunaffected
Version
0
Version <
V1.0.11.148
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX35
Default Statusunaffected
Version
0
Version <
V1.0.17.142
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX35v2
Default Statusunaffected
Version
0
Version <
V1.0.17.142
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX41
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX41v2
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX42
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX42v2
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX43
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX43v2
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX45
Default Statusunaffected
Version
0
Version <
V1.0.17.142
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX49S
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX50
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX50v2
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX54S
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX54Sv2
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX80
Default Statusunaffected
Version
0
Version <
V1.0.11.148
Status
affected
HerstellerNETGEAR
≫
Produkt
RAXE500
Default Statusunaffected
Version
0
Version <
V1.2.14.110
Status
affected
HerstellerNETGEAR
≫
Produkt
RS700
Default Statusunaffected
Version
0
Version <
V1.0.9.6
Status
affected
HerstellerNETGEAR
≫
Produkt
XR1000
Default Statusunaffected
Version
0
Version <
V1.1.0.22
Status
affected
HerstellerNETGEAR
≫
Produkt
XR1000v2
Default Statusunaffected
Version
0
Version <
V1.1.0.22
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.05% | 0.613 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NETGEAR | 4.9 | 0 | 0 |
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://www.netgear.com/support/product/rax20/
https://www.netgear.com/support/product/rax35v2/
https://www.netgear.com/support/product/rax41/
https://www.netgear.com/support/product/rax41v2/
https://www.netgear.com/support/product/rax42v2/
https://www.netgear.com/support/product/rax42/
https://www.netgear.com/support/product/rax43/
https://www.netgear.com/support/product/rax43v2/
https://www.netgear.com/support/product/rax45/
https://www.netgear.com/support/product/rax50/
https://www.netgear.com/support/product/xr1000/
https://www.netgear.com/support/product/xr1000v2/
https://www.netgear.com/support/product/rax50v2/
https://www.netgear.com/support/product/rax49s/
https://www.netgear.com/support/product/raxe500/
https://www.netgear.com/support/product/mr70/
https://www.netgear.com/support/product/mr60/
https://www.netgear.com/support/product/ms60/
https://www.netgear.com/support/product/ms70/
https://www.netgear.com/support/product/rax200/
https://www.netgear.com/support/product/rax80/
https://www.netgear.com/support/product/rs700/
https://www.netgear.com/support/product/rax35/
https://www.netgear.com/support/product/mr90/
https://www.netgear.com/support/product/ms90/
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory