8.1

CVE-2026-9213

Insufficient input validation in certain NETGEAR routers

A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetgearMr70 Firmware Version < 1.0.4.48
   NetgearMr70 Version-
NetgearMs70 Firmware Version < 1.0.4.48
   NetgearMs70 Version-
NetgearRaxe500 Firmware Version < 1.2.14.114
   NetgearRaxe500 Version-
NetgearXr1000 Firmware Version < 1.0.2.86
   NetgearXr1000 Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.314
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NETGEAR 6.9 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.netgear.com/support/product/xr1000/
Product
https://www.netgear.com/support/product/raxe500/
Product
https://www.netgear.com/support/product/mr70/
Product
https://www.netgear.com/support/product/ms70/
Product
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
Vendor Advisory