CVE-2026-9211
HIGH WAF: Medium
CVSS 8.8
Published: 2026-06-09
CWE-20
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
WAF Coverage Analysis
Improper Input Validation
Medium WAF Coverage
OWASP: A03:2021 Injection
920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| netgear | cax30_firmware | up to 2.2.1.4 |
| netgear | rax30_firmware | up to 1.0.10.94 |
| netgear | rax5_firmware | up to 1.0.5.34 |
| netgear | raxe300_firmware | up to 1.0.10.72 |
References
- kb.netgear.com (Vendor Advisory)
- www.netgear.com (Product)
- www.netgear.com (Product)
- www.netgear.com (Product)
- www.netgear.com (Product)