Junglewise Threat Intelligence

CVE-2026-9216: NETGEAR RAX series insufficient input validation in management UI

CVE-2026-9216 · Severity: low · CVSS 3.5 · Published 2026-09-08

Executive brief

NETGEAR RAX series routers contain a vulnerability in their management interface that allows anyone with WiFi access to crash the admin UI. While this disrupts remote management of the router, the core WiFi network and internet connectivity remain unaffected, and no data breach or configuration tampering is possible.

Technical details

The vulnerability is an insufficient input validation flaw in NETGEAR RAX series router management interfaces. An attacker with network-adjacent access (WiFi credentials) can craft malicious input that crashes the management UI without requiring authentication. The attack is limited to denial of service of the management interface; core router services and WiFi availability are not impacted. Patches are available in fixed firmware versions for all affected models: RAX30 (V1.0.9.92), RAX35 (V1.0.10.72), RAX38 (V1.0.6.106), RAX40 (V1.0.6.106), and RAXE300 (V1.0.10.72).

Affected products

  • NETGEAR RAX30 before V1.0.9.92
  • NETGEAR RAX35 before V1.0.10.72
  • NETGEAR RAX38 before V1.0.6.106
  • NETGEAR RAX40 before V1.0.6.106
  • NETGEAR RAXE300 before V1.0.10.72

Timeline

  • 2026-09-08: disclosed

References

Related threats