Junglewise Threat Intelligence

CVE-2026-9212: NETGEAR multiple router models command execution via local network

CVE-2026-9212 · Severity: info · CVSS 5.6 · Published 2026-06-09

Vendors: NETGEAR.

Executive brief

Multiple NETGEAR router and mesh system models are affected by a security flaw that allows users on the local network to execute unauthorized commands. This could allow an attacker to access sensitive information or change the device's configuration. To exploit this, an attacker must already have access to the local network, such as through Wi-Fi or a physical connection.

Technical details

This vulnerability stems from a combination of missing authentication for critical functions (CWE-306) and improper input validation (CWE-20) within the management interface of several NETGEAR models. An attacker with low-privileged access to the local network (adjacent) can exploit these weaknesses to execute arbitrary commands on the device. Successful exploitation can lead to high confidentiality impact and the ability to modify certain system configurations. The vulnerability affects a wide range of products including Orbi, Nighthawk, and RAX series routers.

Affected products

  • NETGEAR LBR1020
  • NETGEAR LBR20
  • NETGEAR R6700AX
  • NETGEAR R7800
  • NETGEAR R9000
  • NETGEAR RAX10
  • NETGEAR RAX120
  • NETGEAR RAX120v2
  • NETGEAR RAX36S
  • NETGEAR RAX70
  • NETGEAR RAX78
  • NETGEAR RBR10
  • NETGEAR RBR20
  • NETGEAR RBR350
  • NETGEAR RBR40
  • NETGEAR RBR50
  • NETGEAR RBS10
  • NETGEAR RBS20
  • NETGEAR RBS350
  • NETGEAR RBS40
  • NETGEAR RBS50
  • NETGEAR XR450
  • NETGEAR XR500

Timeline

  • 2026-06-09: disclosed

References