CVE-2026-11814
4.9
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber
Summary
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NETGEAR | BE9300 | 0 < V1.0.1.84 | affected |
| NETGEAR | MR60 | 0 < V1.1.8.142 | affected |
| NETGEAR | MS60 | 0 < V1.1.8.142 | affected |
| NETGEAR | R6700AX | 0 < V1.0.18.164 | affected |
| NETGEAR | RAX10 | 0 < V1.0.5.50 | affected |
| NETGEAR | RAX120 | 0 < V1.2.10.56 | affected |
| NETGEAR | RAX120v2 | 0 < V1.2.10.56 | affected |
| NETGEAR | RAX20 | 0 < V1.0.17.142 | affected |
| NETGEAR | RAX28 | 0 < V1.0.14.108 | affected |
| NETGEAR | RAX29 | 0 < V1.0.14.108 | affected |
| NETGEAR | RAX30 | 0 < V1.0.14.108 | affected |
| NETGEAR | RAX36S | 0 < V1.0.5.50 | affected |
| NETGEAR | RAX43 | 0 < V1.0.17.142 | affected |
| NETGEAR | RAX45 | 0 < V1.0.17.142 | affected |
| NETGEAR | RAX50 | 0 < V1.0.17.142 | affected |
| NETGEAR | RAX70 | 0 < V1.0.19.172 | affected |
| NETGEAR | RBR760 | 0 < V6.3.8.11 | affected |
| NETGEAR | RBS760 | 0 < V6.3.8.11 | affected |
| NETGEAR | RS100 | 0 < V1.0.1.80 | affected |
| NETGEAR | RS200 | 0 < V1.0.1.90 | affected |
| NETGEAR | RS280 | 0 < V1.0.1.90 | affected |
| NETGEAR | RS300 | 0 < V1.0.1.90 | affected |
| NETGEAR | RS500 | 0 < V1.0.1.90 | affected |
| NETGEAR | RS600 | 0 < V1.0.1.90 | affected |
| NETGEAR | RS70 | 0 < V1.0.1.80 | affected |
| NETGEAR | RS90 | 0 < V1.0.1.80 | affected |
Weaknesses
- CWE-295: CWE-295 Improper certificate validation
References
- https://www.netgear.com/support/product/mr60/
- https://www.netgear.com/support/product/be9300/
- https://www.netgear.com/support/product/ms60/
- https://www.netgear.com/support/product/r6700ax/
- https://www.netgear.com/support/product/rax10/
- https://www.netgear.com/support/product/rax120/
- https://www.netgear.com/support/product/rax120v2/
- https://www.netgear.com/support/product/rax20/
- https://www.netgear.com/support/product/rax29/
- https://www.netgear.com/support/product/rax28/
- https://www.netgear.com/support/product/rax30/
- https://www.netgear.com/support/product/rax36s/
- https://www.netgear.com/support/product/rax45/
- https://www.netgear.com/support/product/rax43/
- https://www.netgear.com/support/product/rax50/
- https://www.netgear.com/support/product/rax70/
- https://www.netgear.com/support/product/rbr760/
- https://www.netgear.com/support/product/rs280/
- https://www.netgear.com/support/product/rbs760/
- https://www.netgear.com/support/product/rs200/
- https://www.netgear.com/support/product/rs300/
- https://www.netgear.com/support/product/rs100/
- https://www.netgear.com/support/product/rs70/
- https://www.netgear.com/support/product/rs600/
- https://www.netgear.com/support/product/rs500/
- https://www.netgear.com/support/product/rs90/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.