6.8

CVE-2026-11814

Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Be9300 Firmware Version < 1.0.1.84
   Netgear ≫ Be9300 Version -
Netgear ≫ Mr60 Firmware Version < 1.1.8.142
   Netgear ≫ Mr60 Version -
Netgear ≫ Ms60 Firmware Version < 1.1.8.142
   Netgear ≫ Ms60 Version -
Netgear ≫ R6700ax Firmware Version < 1.0.18.164
   Netgear ≫ R6700ax Version -
Netgear ≫ Rax10 Firmware Version < 1.0.5.50
   Netgear ≫ Rax10 Version -
Netgear ≫ Rax120 Firmware Version < 1.2.10.56
   Netgear ≫ Rax120 Version -
Netgear ≫ Rax120v2 Firmware Version < 1.2.10.56
   Netgear ≫ Rax120v2 Version -
Netgear ≫ Rax20 Firmware Version < 1.0.17.142
   Netgear ≫ Rax20 Version -
Netgear ≫ Rax28 Firmware Version < 1.0.14.108
   Netgear ≫ Rax28 Version -
Netgear ≫ Rax29 Firmware Version < 1.0.14.108
   Netgear ≫ Rax29 Version -
Netgear ≫ Rax30 Firmware Version < 1.0.14.108
   Netgear ≫ Rax30 Version -
Netgear ≫ Rax36s Firmware Version < 1.0.5.50
   Netgear ≫ Rax36s Version -
Netgear ≫ Rax43 Firmware Version < 1.0.17.142
   Netgear ≫ Rax43 Version -
Netgear ≫ Rax45 Firmware Version < 1.0.17.142
   Netgear ≫ Rax45 Version -
Netgear ≫ Rax50 Firmware Version < 1.0.17.142
   Netgear ≫ Rax50 Version -
Netgear ≫ Rax70 Firmware Version < 1.0.19.172
   Netgear ≫ Rax70 Version -
Netgear ≫ Rbr760 Firmware Version < 6.3.8.11
   Netgear ≫ Rbr760 Version -
Netgear ≫ Rbs760 Firmware Version < 6.3.8.11
   Netgear ≫ Rbs760 Version -
Netgear ≫ Rs100 Firmware Version < 1.0.1.80
   Netgear ≫ Rs100 Version -
Netgear ≫ Rs200 Firmware Version < 1.0.1.90
   Netgear ≫ Rs200 Version -
Netgear ≫ Rs280 Firmware Version < 1.0.1.90
   Netgear ≫ Rs280 Version -
Netgear ≫ Rs300 Firmware Version < 1.0.1.90
   Netgear ≫ Rs300 Version -
Netgear ≫ Rs500 Firmware Version < 1.0.1.90
   Netgear ≫ Rs500 Version -
Netgear ≫ Rs600 Firmware Version < 1.0.1.90
   Netgear ≫ Rs600 Version -
Netgear ≫ Rs70 Firmware Version < 1.0.1.80
   Netgear ≫ Rs70 Version -
Netgear ≫ Rs90 Firmware Version < 1.0.1.80
   Netgear ≫ Rs90 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.83% 0.541
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 1.6 5.2
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
NETGEAR 4.9 0 0
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://www.netgear.com/support/product/rax20/
Product
https://www.netgear.com/support/product/rax43/
Product
https://www.netgear.com/support/product/rax45/
Product
https://www.netgear.com/support/product/rax50/
Product
https://www.netgear.com/support/product/rbs760/
Product
https://www.netgear.com/support/product/rbr760/
Product
https://www.netgear.com/support/product/mr60/
Product
https://www.netgear.com/support/product/ms60/
Product
https://www.netgear.com/support/product/rax120v2/
Product
https://www.netgear.com/support/product/rax30/
Product
https://www.netgear.com/support/product/r6700ax/
Product
https://www.netgear.com/support/product/rax10/
Product
https://www.netgear.com/support/product/rax120/
Product
https://www.netgear.com/support/product/rax70/
Product
https://www.netgear.com/support/product/rax36s/
Product
https://www.netgear.com/support/product/be9300/
Product
https://www.netgear.com/support/product/rax29/
Product
https://www.netgear.com/support/product/rax28/
Product
https://www.netgear.com/support/product/rs280/
Product
https://www.netgear.com/support/product/rs200/
Product
https://www.netgear.com/support/product/rs300/
Product
https://www.netgear.com/support/product/rs100/
Product
https://www.netgear.com/support/product/rs70/
Product
https://www.netgear.com/support/product/rs600/
Product
https://www.netgear.com/support/product/rs500/
Product
https://www.netgear.com/support/product/rs90/
Product
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory
Vendor Advisory