CVE-2026-9212

Severity CVSS v4.0:
MEDIUM
Type:
CWE-20 Input Validation
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:lbr1020_firmware:*:*:*:*:*:*:*:* 2.6.4.60 (excluding)
cpe:2.3:h:netgear:lbr1020:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:lbr20_firmware:*:*:*:*:*:*:*:* 2.7.6.8 (excluding)
cpe:2.3:h:netgear:lbr20:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6700ax_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6700ax:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r7800_firmware:*:*:*:*:*:*:*:* 1.0.4.96 (excluding)
cpe:2.3:h:netgear:r7800:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r9000_firmware:*:*:*:*:*:*:*:* 1.0.6.46 (excluding)
cpe:2.3:h:netgear:r9000:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax10_firmware:*:*:*:*:*:*:*:* 1.0.5.50 (excluding)
cpe:2.3:h:netgear:rax10:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax120_firmware:*:*:*:*:*:*:*:* 1.2.10.56 (excluding)
cpe:2.3:h:netgear:rax120:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax120:1.0:*:*:*:*:*:*:*