4.9

CVE-2026-11814

Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNETGEAR
Produkt BE9300
Default Statusunaffected
Version 0
Version < V1.0.1.84
Status affected
HerstellerNETGEAR
Produkt MR60
Default Statusunaffected
Version 0
Version < V1.1.8.142
Status affected
HerstellerNETGEAR
Produkt MS60
Default Statusunaffected
Version 0
Version < V1.1.8.142
Status affected
HerstellerNETGEAR
Produkt R6700AX
Default Statusunaffected
Version 0
Version < V1.0.18.164
Status affected
HerstellerNETGEAR
Produkt RAX10
Default Statusunaffected
Version 0
Version < V1.0.5.50
Status affected
HerstellerNETGEAR
Produkt RAX120
Default Statusunaffected
Version 0
Version < V1.2.10.56
Status affected
HerstellerNETGEAR
Produkt RAX120v2
Default Statusunaffected
Version 0
Version < V1.2.10.56
Status affected
HerstellerNETGEAR
Produkt RAX20
Default Statusunaffected
Version 0
Version < V1.0.17.142
Status affected
HerstellerNETGEAR
Produkt RAX28
Default Statusunaffected
Version 0
Version < V1.0.14.108
Status affected
HerstellerNETGEAR
Produkt RAX29
Default Statusunaffected
Version 0
Version < V1.0.14.108
Status affected
HerstellerNETGEAR
Produkt RAX30
Default Statusunaffected
Version 0
Version < V1.0.14.108
Status affected
HerstellerNETGEAR
Produkt RAX36S
Default Statusunaffected
Version 0
Version < V1.0.5.50
Status affected
HerstellerNETGEAR
Produkt RAX43
Default Statusunaffected
Version 0
Version < V1.0.17.142
Status affected
HerstellerNETGEAR
Produkt RAX45
Default Statusunaffected
Version 0
Version < V1.0.17.142
Status affected
HerstellerNETGEAR
Produkt RAX50
Default Statusunaffected
Version 0
Version < V1.0.17.142
Status affected
HerstellerNETGEAR
Produkt RAX70
Default Statusunaffected
Version 0
Version < V1.0.19.172
Status affected
HerstellerNETGEAR
Produkt RBR760
Default Statusunaffected
Version 0
Version < V6.3.8.11
Status affected
HerstellerNETGEAR
Produkt RBS760
Default Statusunaffected
Version 0
Version < V6.3.8.11
Status affected
HerstellerNETGEAR
Produkt RS100
Default Statusunaffected
Version 0
Version < V1.0.1.80
Status affected
HerstellerNETGEAR
Produkt RS200
Default Statusunaffected
Version 0
Version < V1.0.1.90
Status affected
HerstellerNETGEAR
Produkt RS280
Default Statusunaffected
Version 0
Version < V1.0.1.90
Status affected
HerstellerNETGEAR
Produkt RS300
Default Statusunaffected
Version 0
Version < V1.0.1.90
Status affected
HerstellerNETGEAR
Produkt RS500
Default Statusunaffected
Version 0
Version < V1.0.1.90
Status affected
HerstellerNETGEAR
Produkt RS600
Default Statusunaffected
Version 0
Version < V1.0.1.90
Status affected
HerstellerNETGEAR
Produkt RS70
Default Statusunaffected
Version 0
Version < V1.0.1.80
Status affected
HerstellerNETGEAR
Produkt RS90
Default Statusunaffected
Version 0
Version < V1.0.1.80
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.83% 0.541
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NETGEAR 4.9 0 0
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://www.netgear.com/support/product/rax20/
https://www.netgear.com/support/product/rax43/
https://www.netgear.com/support/product/rax45/
https://www.netgear.com/support/product/rax50/
https://www.netgear.com/support/product/rbs760/
https://www.netgear.com/support/product/rbr760/
https://www.netgear.com/support/product/mr60/
https://www.netgear.com/support/product/ms60/
https://www.netgear.com/support/product/rax120v2/
https://www.netgear.com/support/product/rax30/
https://www.netgear.com/support/product/r6700ax/
https://www.netgear.com/support/product/rax10/
https://www.netgear.com/support/product/rax120/
https://www.netgear.com/support/product/rax70/
https://www.netgear.com/support/product/rax36s/
https://www.netgear.com/support/product/be9300/
https://www.netgear.com/support/product/rax29/
https://www.netgear.com/support/product/rax28/
https://www.netgear.com/support/product/rs280/
https://www.netgear.com/support/product/rs200/
https://www.netgear.com/support/product/rs300/
https://www.netgear.com/support/product/rs100/
https://www.netgear.com/support/product/rs70/
https://www.netgear.com/support/product/rs600/
https://www.netgear.com/support/product/rs500/
https://www.netgear.com/support/product/rs90/
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory