CVE-2026-11734: Device administrator can interrupt the normal operation of some NETGEAR Nighthawk devices.

Published Aug 11, 2026
·
Updated

A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.

Affected Software

31 affected components
NETGEAR Nighthawk devices
All of the following
Netgear Mr70 Firmware<1.0.4.48
Netgear Mr70
All of the following
Netgear Mr90 Firmware<1.0.2.46
Netgear MR90
All of the following
Netgear Ms70 Firmware<=1.0.4.48
Netgear Ms70
All of the following
Netgear Ms90 Firmware<1.0.2.46
Netgear MS90
All of the following
Netgear Rax41 Firmware<1.1.6.36
Netgear RAX41
All of the following
Netgear Rax41v2 Firmware<1.1.6.36
Netgear RAX41v2
All of the following
Netgear Rax42 Firmware<1.1.6.36
Netgear RAX42
All of the following
Netgear Rax42v2 Firmware<1.1.6.36
Netgear RAX42v2
All of the following
Netgear Rax43 Firmware<1.1.6.36
Netgear RAX43
All of the following
Netgear Rax43v2 Firmware<1.1.6.36
Netgear RAX43v2
All of the following
Netgear Rax49s Firmware<1.1.6.36
Netgear RAX49S
All of the following
Netgear Rax50 Firmware<1.1.6.36
Netgear RAX50
All of the following
Netgear Rax50v2 Firmware<1.1.6.36
Netgear RAX50v2
All of the following
Netgear Rax54s Firmware<1.1.6.36
Netgear Rax54s
All of the following
Netgear Rax54sv2 Firmware<1.1.6.36
Netgear RAX54Sv2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade NETGEAR MR70 (Nighthawk Mesh WiFi 6 Router) to a version that resolves this vulnerability.

    Fixed in V1.0.4.48
  2. Upgrade

    Upgrade NETGEAR MR90 (Nighthawk Tri-band Mesh WiFi 6E Router) to a version that resolves this vulnerability.

    Fixed in V1.0.2.46
  3. Upgrade

    Upgrade NETGEAR MS70 (Nighthawk Mesh WiFi 6 Add-on Satellite) to a version that resolves this vulnerability.

    Fixed in V1.0.4.48
  4. Upgrade

    Upgrade NETGEAR MS90 (Nighthawk Tri-band Mesh WiFi 6E Add-on Satellite) to a version that resolves this vulnerability.

    Fixed in V1.0.2.46
  5. Upgrade

    Upgrade NETGEAR RAX41 (Nighthawk AX5 5-Stream AX3600 WiFi Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  6. Upgrade

    Upgrade NETGEAR RAX41v2 (Nighthawk AX5 5-Stream AX3600 WiFi Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  7. Upgrade

    Upgrade NETGEAR RAX42 (EoS) (Nighthawk AX5 5-Stream AX4200 WiFi Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  8. Upgrade

    Upgrade NETGEAR RAX42v2 (Nighthawk AX5 5-Stream AX4200 WiFi Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  9. Upgrade

    Upgrade NETGEAR RAX43 (Nighthawk AX5 5-Stream AX4200 WiFi Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  10. Upgrade

    Upgrade NETGEAR RAX43v2 (Nighthawk AX5 5-Stream AX4200 WiFi Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  11. Upgrade

    Upgrade NETGEAR RAX49S (Nighthawk AX6 6-Stream AX5300 WiFi Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  12. Upgrade

    Upgrade NETGEAR RAX50 (Nighthawk AX6 6-Stream AX5400 WiFi 6 Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  13. Upgrade

    Upgrade NETGEAR RAX50v2 (Nighthawk AX6 6-Stream AX5400 WiFi 6 Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  14. Upgrade

    Upgrade NETGEAR RAX54S (Nighthawk AX6 6-Stream AX5400 WiFi Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  15. Upgrade

    Upgrade NETGEAR RAX54Sv2 (Nighthawk AX6 6-Stream AX5400 WiFi Router) to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  16. Compensating control

    For models marked (EoS) (MR70, RAX41, RAX42), retire these devices and upgrade to a newer NETGEAR device for continued security support (no security updates are planned).

Event History

Aug 11, 2026
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-11734?

CVE-2026-11734 has a risk rating of 21, indicating a critical vulnerability.

2

How do I fix CVE-2026-11734?

To mitigate CVE-2026-11734, ensure that your NETGEAR Nighthawk device firmware is updated to the latest version provided by NETGEAR.

3

Which devices are affected by CVE-2026-11734?

CVE-2026-11734 affects specific NETGEAR Nighthawk models, including MR70, MR90, and MS90.

4

What is the impact of CVE-2026-11734?

The impact of CVE-2026-11734 is that an authenticated administrator can induce a buffer overflow, causing the device to become temporarily unavailable.

5

When was CVE-2026-11734 published?

CVE-2026-11734 was published on August 11, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203