CVE-2026-9212

HIGH WAF: Medium
CVSS 8.0 Published: 2026-06-09
CWE-20

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

WAF Coverage Analysis

Improper Input Validation Medium WAF Coverage

OWASP: A03:2021 Injection

920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection

Affected Software

VendorProductVersion
netgearlbr1020_firmwareup to 2.6.4.60
netgearlbr20_firmwareup to 2.7.6.8
netgearr6700ax_firmware-
netgearr7800_firmwareup to 1.0.4.96
netgearr9000_firmwareup to 1.0.6.46
netgearrax10_firmwareup to 1.0.5.50
netgearrax120_firmwareup to 1.2.10.56
netgearrax36s_firmwareup to 1.0.5.50
netgearrax70_firmwareup to 1.0.19.172
netgearrax78_firmwareup to 1.0.19.172

References

Back to CVE Database