8.8
CVE-2026-9211
- EPSS 0.24%
- Veröffentlicht 09.06.2026 15:50:48
- Zuletzt bearbeitet 23.07.2026 08:10:00
- CVE-Watchlists
- Unerledigt
Certain NETGEAR routers allow unauthenticated users to gain control of the router
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Cax30 Firmware Version < 2.2.1.4
Netgear ≫ Rax30 Firmware Version < 1.0.10.94
Netgear ≫ Rax5 Firmware Version < 1.0.5.34
Netgear ≫ Raxe300 Firmware Version < 1.0.10.72
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.141 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NETGEAR | 5.2 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://www.netgear.com/support/product/cax30/
https://www.netgear.com/support/product/rax30/
https://www.netgear.com/support/product/rax5/
https://www.netgear.com/support/product/raxe300/
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory