Executive brief
A security vulnerability has been identified in several NETGEAR routers and mesh WiFi systems that could allow an authorized administrator to compromise the device's integrity. To exploit this, an attacker must already have administrative credentials and be connected to the local network. While the risk is mitigated by the requirement for high-level access, it could allow a malicious insider or a compromised admin account to make unauthorized changes to the router's core configuration.
Technical details
An improper input validation vulnerability (CWE-20) exists in the management interface of multiple NETGEAR router models. The flaw allows an attacker with administrative privileges, who is connected via the local network (Adjacent), to bypass validation checks and tamper with the device's integrity. This could potentially lead to unauthorized configuration changes or persistence. The attack requires high privileges (PR:H) and no user interaction. Affected models include various Nighthawk, Orbi, and RAX series devices. Users are advised to check NETGEAR's support pages for firmware updates.
Affected products
- NETGEAR MR60
- NETGEAR MR70
- NETGEAR MR80
- NETGEAR MS60
- NETGEAR MS70
- NETGEAR MS80
- NETGEAR R6400v2
- NETGEAR R6700v3
- NETGEAR R6900P
- NETGEAR R7000
- NETGEAR R7000P
- NETGEAR R7960P
- NETGEAR R8000P
- NETGEAR R8500
- NETGEAR RAX20
- NETGEAR RAX35v2
- NETGEAR RAX40v2
- NETGEAR RAX41
- NETGEAR RAX42
- NETGEAR RAX43
- NETGEAR RAX45
- NETGEAR RAX48
- NETGEAR RAX50
- NETGEAR RAX50S
- NETGEAR RAXE450
- NETGEAR RAXE500
- NETGEAR XR1000
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
References
- https://www.netgear.com/support/product/mr60/
- https://www.netgear.com/support/product/mr70/
- https://www.netgear.com/support/product/mr80/
- https://www.netgear.com/support/product/ms60/
- https://www.netgear.com/support/product/ms70/
- https://www.netgear.com/support/product/ms80/
- https://www.netgear.com/support/product/r6400v2/