CVE-2026-11739: Command injection vulnerability in some NETGEAR Nighthawk devices

Published Aug 11, 2026
·
Updated

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.

Affected Software

55 affected components
Netgear Nighthawk
All of the following
Netgear Ms90 Firmware<1.0.2.46
Netgear MS90
All of the following
Netgear Rax20 Firmware<1.0.17.142
Netgear RAX20
All of the following
Netgear Rax200 Firmware<1.0.11.148
Netgear RAX200
All of the following
Netgear Rax35 Firmware<1.0.17.142
Netgear RAX35
All of the following
Netgear Rax35v2 Firmware<1.0.17.142
Netgear RAX35v2
All of the following
Netgear Rax41 Firmware<1.1.6.36
Netgear RAX41
All of the following
Netgear Rax41v2 Firmware<1.1.6.36
Netgear RAX41v2
All of the following
Netgear Rax42 Firmware<1.1.6.36
Netgear RAX42
All of the following
Netgear Rax42v2 Firmware<1.1.6.36
Netgear RAX42v2
All of the following
Netgear Rax43 Firmware<1.1.6.36
Netgear RAX43
All of the following
Netgear Rax43v2 Firmware<1.1.6.36
Netgear RAX43v2
All of the following
Netgear Rax45 Firmware<1.0.17.142
Netgear RAX45
All of the following
Netgear Rax49s Firmware<1.1.6.36
Netgear RAX49S
All of the following
Netgear Rax50 Firmware<1.1.6.36
Netgear RAX50
All of the following
Netgear Rax50v2 Firmware<1.1.6.36
Netgear RAX50v2
All of the following
Netgear Rax54s Firmware<1.1.6.36
Netgear Rax54s
All of the following
Netgear Rax54sv2 Firmware<1.1.6.36
Netgear RAX54Sv2
All of the following
Netgear Rax80 Firmware<1.0.11.148
Netgear RAX80
All of the following
Netgear Raxe500 Firmware<1.2.14.110
Netgear RAXE500
All of the following
Netgear Rs700 Firmware<1.0.9.6
Netgear RS700
All of the following
Netgear Xr1000 Firmware<1.1.0.22
Netgear XR1000
All of the following
Netgear Xr1000v2 Firmware<1.1.0.22
Netgear XR1000v2
All of the following
Netgear Mr60 Firmware<1.1.8.142
Netgear MR60
All of the following
Netgear Mr70 Firmware<1.0.4.48
Netgear Mr70
All of the following
Netgear Mr90 Firmware<1.0.2.46
Netgear MR90
All of the following
Netgear Ms60 Firmware<1.1.8.142
Netgear MS60
All of the following
Netgear Ms70 Firmware<1.0.4.48
Netgear Ms70

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade NETGEAR Nighthawk MR60 / MS60 to a version that resolves this vulnerability.

    Fixed in V1.1.8.142
  2. Upgrade

    Upgrade NETGEAR Nighthawk MR70 / MS70 to a version that resolves this vulnerability.

    Fixed in V1.0.4.48
  3. Upgrade

    Upgrade NETGEAR Nighthawk MR90 / MS90 to a version that resolves this vulnerability.

    Fixed in V1.0.2.46
  4. Upgrade

    Upgrade NETGEAR Nighthawk RAX20 to a version that resolves this vulnerability.

    Fixed in V1.0.17.142
  5. Upgrade

    Upgrade NETGEAR Nighthawk RAX200 to a version that resolves this vulnerability.

    Fixed in V1.0.11.148
  6. Upgrade

    Upgrade NETGEAR Nighthawk RAX35 to a version that resolves this vulnerability.

    Fixed in V1.0.17.142
  7. Upgrade

    Upgrade NETGEAR Nighthawk RAX35v2 to a version that resolves this vulnerability.

    Fixed in V1.0.17.142
  8. Upgrade

    Upgrade NETGEAR Nighthawk RAX41 / RAX41v2 / RAX42 / RAX42v2 / RAX43 / RAX43v2 / RAX45 to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  9. Upgrade

    Upgrade NETGEAR Nighthawk RAX45 to a version that resolves this vulnerability.

    Fixed in V1.0.17.142
  10. Upgrade

    Upgrade NETGEAR Nighthawk RAX49S / RAX50 / RAX50v2 / RAX54S / RAX54Sv2 to a version that resolves this vulnerability.

    Fixed in V1.1.6.36
  11. Upgrade

    Upgrade NETGEAR Nighthawk RAX80 to a version that resolves this vulnerability.

    Fixed in V1.0.11.148
  12. Upgrade

    Upgrade NETGEAR Nighthawk RAXE500 to a version that resolves this vulnerability.

    Fixed in V1.2.14.110
  13. Upgrade

    Upgrade NETGEAR Nighthawk RS700 to a version that resolves this vulnerability.

    Fixed in V1.0.9.6
  14. Upgrade

    Upgrade NETGEAR Nighthawk XR1000 / XR1000v2 to a version that resolves this vulnerability.

    Fixed in V1.1.0.22
  15. Compensating control

    For models marked (EoS): retire the affected devices and upgrade to a newer NETGEAR device for continued security support (no security updates are planned).

Event History

Aug 11, 2026
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-11739?

The severity of CVE-2026-11739 is rated as 55 on the risk scale, indicating a medium level of risk.

2

How do I fix CVE-2026-11739?

To fix CVE-2026-11739, ensure that your NETGEAR Nighthawk device is updated with the latest firmware provided by NETGEAR.

3

What devices are affected by CVE-2026-11739?

CVE-2026-11739 affects specific models of NETGEAR Nighthawk devices that have the command injection vulnerability.

4

Can CVE-2026-11739 be exploited remotely?

CVE-2026-11739 requires an attacker to be network-adjacent, meaning they must be on the local network to exploit the vulnerability.

5

What are the consequences of CVE-2026-11739?

Exploitation of CVE-2026-11739 can lead to the compromise of the confidentiality and integrity of the affected NETGEAR Nighthawk device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203