8.1
CVE-2026-9213
- EPSS 0.4%
- Veröffentlicht 09.06.2026 15:50:46
- Zuletzt bearbeitet 23.07.2026 08:10:00
- CVE-Watchlists
- Unerledigt
Insufficient input validation in certain NETGEAR routers
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Mr70 Firmware Version < 1.0.4.48
Netgear ≫ Ms70 Firmware Version < 1.0.4.48
Netgear ≫ Raxe500 Firmware Version < 1.2.14.114
Netgear ≫ Xr1000 Firmware Version < 1.0.2.86
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.314 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NETGEAR | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://www.netgear.com/support/product/xr1000/
https://www.netgear.com/support/product/raxe500/
https://www.netgear.com/support/product/mr70/
https://www.netgear.com/support/product/ms70/
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory