CVE-2026-9216

Summary

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.

Affected Software

VendorProductVersion RangeStatus
NETGEARRAX300 < V1.0.9.92affected
NETGEARRAX350 < V1.0.10.72affected
NETGEARRAX380 < V1.0.6.106affected
NETGEARRAX400 < V1.0.6.106affected
NETGEARRAXE3000 < V1.0.10.72affected

Weaknesses

  • CWE-121: CWE-121 Stack-based buffer overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References