Junglewise Threat Intelligence

CVE-2026-9213: NETGEAR Gaming Routers remote code execution via traffic tampering

CVE-2026-9213 · Severity: info · CVSS 6.9 · Published 2026-06-09

Executive brief

A security vulnerability has been identified in several NETGEAR gaming routers that could allow an attacker to take control of the device. By intercepting and modifying internet traffic, a malicious actor could execute unauthorized commands on the router. This could lead to a complete compromise of the home network, allowing attackers to monitor user activity or redirect traffic to malicious websites.

Technical details

The vulnerability is classified as Improper Input Validation (CWE-20) within the firmware of affected NETGEAR gaming routers. An attacker positioned to perform a Man-in-the-Middle (MitM) attack between the router and the Internet can tamper with network traffic to trigger remote code execution. While the attack requires a high degree of network positioning (intercepting ISP-level or upstream traffic), successful exploitation allows for complete system compromise. Affected models include MR70, MS70, RAXE500, and XR1000. Users are advised to check for firmware updates from the vendor.

Affected products

  • NETGEAR MR70
  • NETGEAR MS70
  • NETGEAR RAXE500
  • NETGEAR XR1000

Timeline

  • 2026-06-09: disclosed: CVE published by Netgear via NVD

References

Related threats