8.1

CVE-2026-9213

Insufficient input validation in certain NETGEAR routers

A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Mr70 Firmware Version < 1.0.4.48
   Netgear ≫ Mr70 Version -
Netgear ≫ Ms70 Firmware Version < 1.0.4.48
   Netgear ≫ Ms70 Version -
Netgear ≫ Raxe500 Firmware Version < 1.2.14.114
   Netgear ≫ Raxe500 Version -
Netgear ≫ Xr1000 Firmware Version < 1.0.2.86
   Netgear ≫ Xr1000 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.314
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NETGEAR 6.9 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.netgear.com/support/product/xr1000/
Product
https://www.netgear.com/support/product/raxe500/
Product
https://www.netgear.com/support/product/mr70/
Product
https://www.netgear.com/support/product/ms70/
Product
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
Vendor Advisory