Junglewise Threat Intelligence

CVE-2026-11814: NETGEAR Nighthawk and Orbi routers command injection vulnerability

CVE-2026-11814 · Severity: medium · CVSS 6.8 · Published 2026-08-11

Executive brief

NETGEAR Nighthawk and Orbi WiFi routers contain a command injection vulnerability that allows an attacker positioned on the local network (able to intercept traffic) to execute arbitrary commands on the device. This could compromise the confidentiality and integrity of the router and any devices connected to it, potentially exposing sensitive network data or allowing an attacker to maintain persistent access to the home or office network.

Technical details

This is a command injection vulnerability affecting multiple NETGEAR Nighthawk and Orbi router models. The vulnerability requires the attacker to be network-adjacent with the ability to intercept and modify local network traffic (man-in-the-middle position). The attack allows an unauthenticated attacker to inject and execute arbitrary commands on the affected device, compromising both confidentiality and integrity. The issue is limited to certain region-specific SKUs. Patches are available via firmware updates for all affected models, with specific patched versions provided by NETGEAR.

Affected products

  • NETGEAR BE9300 prior to V1.0.1.84
  • NETGEAR MR60 prior to V1.1.8.142
  • NETGEAR MS60 prior to V1.1.8.142
  • NETGEAR R6700AX prior to V1.0.18.164
  • NETGEAR RAX10 prior to V1.0.5.50
  • NETGEAR RAX120 prior to V1.2.10.56
  • NETGEAR RAX120v2 prior to V1.2.10.56
  • NETGEAR RAX20 prior to V1.0.17.142
  • NETGEAR RAX28 prior to V1.0.14.108
  • NETGEAR RAX29 prior to V1.0.14.108
  • NETGEAR RAX30 prior to V1.0.14.108
  • NETGEAR RAX36S prior to V1.0.5.50
  • NETGEAR RAX43 prior to V1.0.17.142
  • NETGEAR RAX45 prior to V1.0.17.142
  • NETGEAR RAX50 prior to V1.0.17.142
  • NETGEAR RAX70 prior to V1.0.19.172
  • NETGEAR RBR760 prior to V6.3.8.11
  • NETGEAR RBS760 prior to V6.3.8.11
  • NETGEAR RS100 prior to V1.0.1.80
  • NETGEAR RS200 prior to V1.0.1.90
  • NETGEAR RS280 prior to V1.0.1.90
  • NETGEAR RS300 prior to V1.0.1.90
  • NETGEAR RS500 prior to V1.0.1.90
  • NETGEAR RS600 prior to V1.0.1.90
  • NETGEAR RS70 prior to V1.0.1.80
  • NETGEAR RS90 prior to V1.0.1.80

Timeline

  • 2026-08-11: disclosed
  • other: CVE-2026-11814 assigned

References

Related threats