CVE-2026-9216
3.5
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Summary
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NETGEAR | RAX30 | 0 < V1.0.9.92 | affected |
| NETGEAR | RAX35 | 0 < V1.0.10.72 | affected |
| NETGEAR | RAX38 | 0 < V1.0.6.106 | affected |
| NETGEAR | RAX40 | 0 < V1.0.6.106 | affected |
| NETGEAR | RAXE300 | 0 < V1.0.10.72 | affected |
Weaknesses
- CWE-121: CWE-121 Stack-based buffer overflow
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://www.netgear.com/support/product/rax30
- https://www.netgear.com/support/product/rax35
- https://www.netgear.com/support/product/rax38
- https://www.netgear.com/support/product/rax40
- https://www.netgear.com/support/product/raxe300
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.