CVE-2026-11814: Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers

Published Aug 11, 2026
·
Updated

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.

Affected Software

53 affected components
NETGEAR Nighthawk and Orbi routers
All of the following
Netgear Be9300 Firmware<1.0.1.84
Netgear Be9300
All of the following
Netgear Mr60 Firmware<1.1.8.142
Netgear MR60
All of the following
Netgear Ms60 Firmware<1.1.8.142
Netgear MS60
All of the following
Netgear R6700ax Firmware<1.0.18.164
Netgear R6700AX
All of the following
Netgear Rax10 Firmware<1.0.5.50
Netgear RAX10
All of the following
Netgear Rax120 Firmware<1.2.10.56
Netgear RAX120
All of the following
Netgear Rax120v2 Firmware<1.2.10.56
Netgear RAX120v2
All of the following
Netgear Rax20 Firmware<1.0.17.142
Netgear RAX20
All of the following
Netgear Rax28 Firmware<1.0.14.108
Netgear Rax28
All of the following
Netgear Rax29 Firmware<1.0.14.108
Netgear Rax29
All of the following
Netgear RAX30 firmware<1.0.14.108
Netgear RAX30
All of the following
Netgear Rax36s Firmware<1.0.5.50
Netgear Rax36s
All of the following
Netgear Rax43 Firmware<1.0.17.142
Netgear RAX43
All of the following
Netgear Rax45 Firmware<1.0.17.142
Netgear RAX45
All of the following
Netgear Rax50 Firmware<1.0.17.142
Netgear RAX50
All of the following
Netgear Rax70 Firmware<1.0.19.172
Netgear RAX70
All of the following
Netgear Rbr760 Firmware<6.3.8.11
Netgear Rbr760
All of the following
Netgear Rbs760 Firmware<6.3.8.11
Netgear Rbs760
All of the following
Netgear Rs100 Firmware<1.0.1.80
Netgear Rs100
All of the following
Netgear Rs200 Firmware<1.0.1.90
Netgear Rs200
All of the following
Netgear Rs280 Firmware<1.0.1.90
Netgear Rs280
All of the following
Netgear Rs300 Firmware<1.0.1.90
Netgear Rs300
All of the following
Netgear Rs500 Firmware<1.0.1.90
Netgear Rs500
All of the following
Netgear Rs600 Firmware<1.0.1.90
Netgear Rs600
All of the following
Netgear Rs70 Firmware<1.0.1.80
Netgear Rs70
All of the following
Netgear Rs90 Firmware<1.0.1.80
Netgear Rs90

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade NETGEAR Nighthawk/Orbi routers listed in advisory to a version that resolves this vulnerability.

    Fixed in V1.0.1.84
  2. Upgrade

    Upgrade NETGEAR Nighthawk Mesh WiFi 6 Router (MR60) / Nighthawk Mesh WiFi 6 Add-on Satellite (MS60) to a version that resolves this vulnerability.

    Fixed in V1.1.8.142
  3. Upgrade

    Upgrade NETGEAR R6700AX (4-Stream AX1800) to a version that resolves this vulnerability.

    Fixed in 4-Stream AX1800 WiFi 6 Router V1.0.18.164
  4. Upgrade

    Upgrade NETGEAR RAX10 (4-Stream AX1800) to a version that resolves this vulnerability.

    Fixed in V1.0.5.50
  5. Upgrade

    Upgrade NETGEAR RAX120 (Nighthawk AX12 12-Stream) / RAX120v2 (Nighthawk AX12 12-Stream AX6000) to a version that resolves this vulnerability.

    Fixed in V1.2.10.56
  6. Upgrade

    Upgrade NETGEAR RAX20 (4-Stream AX1800) / RAX28 (Nighthawk AX5 5-Stream AX2200) / RAX29 (Nighthawk AX2400) / RAX43 (Nighthawk AX5 5-Stream AX4200) / RAX50 (Nighthawk AX6 6-Stream AX5400) / RAX70 (Nighthawk Tri-band AX8 8-Stream AX6600) to a version that resolves this vulnerability.

    Fixed in V1.0.17.142
  7. Upgrade

    Upgrade NETGEAR RAX28 (Nighthawk AX5 5-Stream AX2200) to a version that resolves this vulnerability.

    Fixed in V1.0.14.108
  8. Upgrade

    Upgrade NETGEAR RAX29 (Nighthawk AX2400) to a version that resolves this vulnerability.

    Fixed in V1.0.14.108
  9. Upgrade

    Upgrade NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400) to a version that resolves this vulnerability.

    Fixed in V1.0.14.108
  10. Upgrade

    Upgrade NETGEAR RAX36S (Nighthawk AX4 4-Stream AX3000) to a version that resolves this vulnerability.

    Fixed in V1.0.5.50
  11. Upgrade

    Upgrade NETGEAR RAX45 (Nighthawk AX6 6-Stream AX4300) / RAX50 (Nighthawk AX6 6-Stream AX5400) / RAX43 (Nighthawk AX5 5-Stream AX4200) to a version that resolves this vulnerability.

    Fixed in V1.0.17.142
  12. Upgrade

    Upgrade NETGEAR RBR760 (Orbi Tri-Band Mesh WiFi 6) / RBS760 (Orbi Tri-Band Mesh WiFi 6 Add-on Satellite) to a version that resolves this vulnerability.

    Fixed in V6.3.8.11
  13. Upgrade

    Upgrade NETGEAR RS100 (Nighthawk WiFi 7 Dual-Band) / RS70 (Nighthawk WiFi 7 Dual-Band) / RS90 (Nighthawk WiFi 7 Dual-Band) to a version that resolves this vulnerability.

    Fixed in V1.0.1.80
  14. Upgrade

    Upgrade NETGEAR RS200 (Nighthawk BE6500 WiFi 7 Dual-Band) to a version that resolves this vulnerability.

    Fixed in V1.0.1.90
  15. Upgrade

    Upgrade NETGEAR RS280 (Nighthawk BE9200 WiFi 7 Tri-Band) / RS300 (Nighthawk BE9300 WiFi 7 Tri-Band) / RS500 (Nighthawk BE12000 WiFi 7 Tri-Band) / RS600 (Nighthawk BE18000 WiFi 7 Tri-Band) to a version that resolves this vulnerability.

    Fixed in V1.0.1.90
  16. Compensating control

    For models marked (EoS) that have reached End-of-Support phase (no security updates planned), retire the affected devices and upgrade to a newer NETGEAR device for continued security support.

Event History

Aug 11, 2026
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-11814?

The severity of CVE-2026-11814 is rated as 60 on the risk scale.

2

How do I fix CVE-2026-11814?

To fix CVE-2026-11814, ensure that your NETGEAR Nighthawk and Orbi routers are updated to the latest firmware version provided by NETGEAR.

3

What devices are affected by CVE-2026-11814?

CVE-2026-11814 affects certain models of NETGEAR Nighthawk and Orbi routers.

4

What type of vulnerability is CVE-2026-11814?

CVE-2026-11814 is classified as a command injection vulnerability.

5

Can an attacker exploit CVE-2026-11814 remotely?

No, an attacker needs to be network-adjacent to exploit CVE-2026-11814 by intercepting and modifying local network traffic.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203