CVE-2026-9212
HIGH WAF: Medium
CVSS 8.0
Published: 2026-06-09
CWE-20
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
WAF Coverage Analysis
Improper Input Validation
Medium WAF Coverage
OWASP: A03:2021 Injection
920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| netgear | lbr1020_firmware | up to 2.6.4.60 |
| netgear | lbr20_firmware | up to 2.7.6.8 |
| netgear | r6700ax_firmware | - |
| netgear | r7800_firmware | up to 1.0.4.96 |
| netgear | r9000_firmware | up to 1.0.6.46 |
| netgear | rax10_firmware | up to 1.0.5.50 |
| netgear | rax120_firmware | up to 1.2.10.56 |
| netgear | rax36s_firmware | up to 1.0.5.50 |
| netgear | rax70_firmware | up to 1.0.19.172 |
| netgear | rax78_firmware | up to 1.0.19.172 |
References
- kb.netgear.com (Patch, Vendor Advisory)
- www.netgear.com (Product)
- www.netgear.com (Product)
- www.netgear.com (Product)
- www.netgear.com (Product)
- www.netgear.com (Product)
- www.netgear.com (Product)
- www.netgear.com (Product)
- www.netgear.com (Product)
- www.netgear.com (Product)