Junglewise Threat Intelligence

CVE-2026-9211: Netgear Multiple Routers improper input validation

CVE-2026-9211 · Severity: info · CVSS 5.2 · Published 2026-06-09

Executive brief

A security vulnerability in several Netgear router models allows an unauthorized person on the same local network to take full control of the device. This could allow an attacker to monitor internet traffic, redirect users to malicious websites, or disable the network entirely. The issue affects home and small office routers used for internet connectivity and local networking.

Technical details

A vulnerability classified as Improper Input Validation (CWE-20) exists in multiple Netgear router models, including CAX30, RAX30, RAX5, and RAXE300. An unauthenticated attacker located on the same local network (adjacent) can exploit this flaw to gain administrative control over the device. Successful exploitation allows for unauthorized configuration changes and full compromise of the router's operation. The vulnerability is triggered without user interaction, though it requires specific network conditions (AT:P). Netgear has acknowledged the issue, and users are advised to check for firmware updates for the affected models.

Affected products

  • Netgear CAX30
  • Netgear RAX30
  • Netgear RAX5
  • Netgear RAXE300

Timeline

  • 2026-06-09: disclosed: CVE published by Netgear via NVD

References

Related threats