8
CVE-2026-9212
- EPSS 0.27%
- Veröffentlicht 09.06.2026 15:50:53
- Zuletzt bearbeitet 23.07.2026 08:10:00
- CVE-Watchlists
- Unerledigt
Insufficient authentication and input validation in certain NETGEAR products
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Lbr1020 Firmware Version < 2.6.4.60
Netgear ≫ Lbr20 Firmware Version < 2.7.6.8
Netgear ≫ R6700ax Firmware Version-
Netgear ≫ R7800 Firmware Version < 1.0.4.96
Netgear ≫ R9000 Firmware Version < 1.0.6.46
Netgear ≫ Rax10 Firmware Version < 1.0.5.50
Netgear ≫ Rax120 Firmware Version < 1.2.10.56
Netgear ≫ Rax36s Firmware Version < 1.0.5.50
Netgear ≫ Rax70 Firmware Version < 1.0.19.172
Netgear ≫ Rax78 Firmware Version < 1.0.19.172
Netgear ≫ Rbr10 Firmware Version-
Netgear ≫ Rbr20 Firmware Version-
Netgear ≫ Rbr350 Firmware Version < 4.4.2.1
Netgear ≫ Rbr40 Firmware Version-
Netgear ≫ Rbr50 Firmware Version-
Netgear ≫ Rbs10 Firmware Version-
Netgear ≫ Rbs20 Firmware Version-
Netgear ≫ Rbs350 Firmware Version < 4.4.2.1
Netgear ≫ Rbs40 Firmware Version-
Netgear ≫ Rbs50 Firmware Version-
Netgear ≫ Xr450 Firmware Version < 2.3.3.136
Netgear ≫ Xr500 Firmware Version < 2.3.3.136
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.183 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NETGEAR | 5.6 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://www.netgear.com/support/product/rbr350/
https://www.netgear.com/support/product/rbs350/
https://www.netgear.com/support/product/rax120v2/
https://www.netgear.com/support/product/lbr20/
https://www.netgear.com/support/product/lbr1020/
https://www.netgear.com/support/product/r6700ax/
https://www.netgear.com/support/product/r9000/
https://www.netgear.com/support/product/r7800/
https://www.netgear.com/support/product/rax10/
https://www.netgear.com/support/product/rax120/
https://www.netgear.com/support/product/rax78/
https://www.netgear.com/support/product/rax70/
https://www.netgear.com/support/product/rbr10/
https://www.netgear.com/support/product/rbr40/
https://www.netgear.com/support/product/rbr50/
https://www.netgear.com/support/product/rbs10/
https://www.netgear.com/support/product/rbs20/
https://www.netgear.com/support/product/rax36s/
https://www.netgear.com/support/product/rbr20/
https://www.netgear.com/support/product/rbs50/
https://www.netgear.com/support/product/xr500/
https://www.netgear.com/support/product/rbs40/
https://www.netgear.com/support/product/xr450/
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory