CVE-2026-11814: Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR Nighthawk/Orbi routers listed in advisoryto a version that resolves this vulnerability.Fixed in V1.0.1.84 - Upgrade
Upgrade
NETGEAR Nighthawk Mesh WiFi 6 Router (MR60) / Nighthawk Mesh WiFi 6 Add-on Satellite (MS60)to a version that resolves this vulnerability.Fixed in V1.1.8.142 - Upgrade
Upgrade
NETGEAR R6700AX (4-Stream AX1800)to a version that resolves this vulnerability.Fixed in 4-Stream AX1800 WiFi 6 Router V1.0.18.164 - Upgrade
Upgrade
NETGEAR RAX10 (4-Stream AX1800)to a version that resolves this vulnerability.Fixed in V1.0.5.50 - Upgrade
Upgrade
NETGEAR RAX120 (Nighthawk AX12 12-Stream) / RAX120v2 (Nighthawk AX12 12-Stream AX6000)to a version that resolves this vulnerability.Fixed in V1.2.10.56 - Upgrade
Upgrade
NETGEAR RAX20 (4-Stream AX1800) / RAX28 (Nighthawk AX5 5-Stream AX2200) / RAX29 (Nighthawk AX2400) / RAX43 (Nighthawk AX5 5-Stream AX4200) / RAX50 (Nighthawk AX6 6-Stream AX5400) / RAX70 (Nighthawk Tri-band AX8 8-Stream AX6600)to a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR RAX28 (Nighthawk AX5 5-Stream AX2200)to a version that resolves this vulnerability.Fixed in V1.0.14.108 - Upgrade
Upgrade
NETGEAR RAX29 (Nighthawk AX2400)to a version that resolves this vulnerability.Fixed in V1.0.14.108 - Upgrade
Upgrade
NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400)to a version that resolves this vulnerability.Fixed in V1.0.14.108 - Upgrade
Upgrade
NETGEAR RAX36S (Nighthawk AX4 4-Stream AX3000)to a version that resolves this vulnerability.Fixed in V1.0.5.50 - Upgrade
Upgrade
NETGEAR RAX45 (Nighthawk AX6 6-Stream AX4300) / RAX50 (Nighthawk AX6 6-Stream AX5400) / RAX43 (Nighthawk AX5 5-Stream AX4200)to a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR RBR760 (Orbi Tri-Band Mesh WiFi 6) / RBS760 (Orbi Tri-Band Mesh WiFi 6 Add-on Satellite)to a version that resolves this vulnerability.Fixed in V6.3.8.11 - Upgrade
Upgrade
NETGEAR RS100 (Nighthawk WiFi 7 Dual-Band) / RS70 (Nighthawk WiFi 7 Dual-Band) / RS90 (Nighthawk WiFi 7 Dual-Band)to a version that resolves this vulnerability.Fixed in V1.0.1.80 - Upgrade
Upgrade
NETGEAR RS200 (Nighthawk BE6500 WiFi 7 Dual-Band)to a version that resolves this vulnerability.Fixed in V1.0.1.90 - Upgrade
Upgrade
NETGEAR RS280 (Nighthawk BE9200 WiFi 7 Tri-Band) / RS300 (Nighthawk BE9300 WiFi 7 Tri-Band) / RS500 (Nighthawk BE12000 WiFi 7 Tri-Band) / RS600 (Nighthawk BE18000 WiFi 7 Tri-Band)to a version that resolves this vulnerability.Fixed in V1.0.1.90 - Compensating control
For models marked (EoS) that have reached End-of-Support phase (no security updates planned), retire the affected devices and upgrade to a newer NETGEAR device for continued security support.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11814?
The severity of CVE-2026-11814 is rated as 60 on the risk scale.
How do I fix CVE-2026-11814?
To fix CVE-2026-11814, ensure that your NETGEAR Nighthawk and Orbi routers are updated to the latest firmware version provided by NETGEAR.
What devices are affected by CVE-2026-11814?
CVE-2026-11814 affects certain models of NETGEAR Nighthawk and Orbi routers.
What type of vulnerability is CVE-2026-11814?
CVE-2026-11814 is classified as a command injection vulnerability.
Can an attacker exploit CVE-2026-11814 remotely?
No, an attacker needs to be network-adjacent to exploit CVE-2026-11814 by intercepting and modifying local network traffic.