CVE-2026-9210: Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router

Published Jun 9, 2026
·
Updated

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

Affected Software

62 affected components
All of the following
Netgear Ex3700 Firmware<1.0.0.100
Netgear EX3700
All of the following
Netgear Ex3800 Firmware<1.0.0.100
Netgear EX3800
All of the following
Netgear Ex6120 Firmware<1.0.0.72
Netgear EX6120
All of the following
Netgear Ex6130 Firmware<1.0.0.54
Netgear EX6130
All of the following
Netgear Mr60 Firmware<1.1.7.132
Netgear MR60
All of the following
Netgear Mr70 Firmware<1.0.3.28
Netgear Mr70
All of the following
Netgear Mr80 Firmware<1.1.7.14
Netgear MR80
All of the following
Netgear Ms60 Firmware<1.1.7.132
Netgear MS60
All of the following
Netgear Ms70 Firmware<1.0.3.28
Netgear Ms70
All of the following
Netgear Ms80 Firmware<1.1.7.14
Netgear MS80
All of the following
Netgear R6400v2 Firmware<1.0.4.128
Netgear R6400v2
All of the following
Netgear R6700v3 Firmware<1.0.4.128
Netgear R6700v3
All of the following
Netgear R6900p Firmware<1.3.3.152
Netgear R6900P
All of the following
Netgear R7000 Firmware<1.0.11.216
Netgear R7000
All of the following
Netgear R7000p Firmware<1.3.3.152
Netgear R7000P
All of the following
Netgear R7960p Firmware<1.4.4.92
Netgear R7960P
All of the following
Netgear R8000p Firmware<1.4.4.92
Netgear R8000P
All of the following
Netgear R8500 Firmware
Netgear R8500
All of the following
Netgear Rax20 Firmware<1.0.18.144
Netgear RAX20
All of the following
Netgear Rax35v2 Firmware<1.0.12.118
Netgear RAX35v2
All of the following
Netgear Rax40v2 Firmware<1.0.12.118
Netgear RAX40v2
All of the following
Netgear Rax41 Firmware<1.0.12.118
Netgear RAX41
All of the following
Netgear Rax42 Firmware<1.0.12.118
Netgear RAX42
All of the following
Netgear Rax43 Firmware<1.0.12.120
Netgear RAX43
All of the following
Netgear Rax48 Firmware<1.0.12.118
Netgear Rax48
All of the following
Netgear Rax50 Firmware<1.0.12.120
Netgear RAX50
All of the following
Netgear Rax50s Firmware<1.0.12.120
Netgear Rax50s
All of the following
Netgear Raxe450 Firmware<1.0.10.86
Netgear RAXE450
All of the following
Netgear Raxe500 Firmware<1.0.10.86
Netgear RAXE500
All of the following
Netgear Xr1000 Firmware<1.0.0.68
Netgear XR1000
All of the following
Netgear Rax45 Firmware<1.0.12.118
Netgear RAX45

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade NETGEAR firmware (listed models) to a version that resolves this vulnerability.

    Fixed in latest
  2. Upgrade

    Upgrade EX3700 AC750 WiFi Range Extender Essentials Edition V1.0.0.100 to a version that resolves this vulnerability.

    Fixed in V1.0.0.100
  3. Upgrade

    Upgrade EX3800 (EoS) AC750 WiFi Range Extender Essentials Edition V1.0.0.100 to a version that resolves this vulnerability.

    Fixed in V1.0.0.100
  4. Upgrade

    Upgrade EX6120 AC1200 Dual Band WiFi Range Extender to a version that resolves this vulnerability.

    Fixed in V1.0.0.72
  5. Upgrade

    Upgrade EX6130 AC1200 WiFi Range Extender to a version that resolves this vulnerability.

    Fixed in V1.0.0.54
  6. Upgrade

    Upgrade MR60 Nighthawk Mesh WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.1.7.132
  7. Upgrade

    Upgrade MR70 Nighthawk Mesh WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.3.28
  8. Upgrade

    Upgrade MR80 Nighthawk Tri-band Mesh WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.1.7.14
  9. Upgrade

    Upgrade MS60 Nighthawk Mesh WiFi 6 Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V1.1.7.132
  10. Upgrade

    Upgrade MS70 Nighthawk Mesh WiFi 6 Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V1.0.3.28
  11. Upgrade

    Upgrade MS80 Nighthawk Tri-band Mesh WiFi 6 Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V1.1.7.14
  12. Upgrade

    Upgrade R6400v2 (EoS) AC1750 Smart WiFi Router 802.11ac Dual Band Gigabit to a version that resolves this vulnerability.

    Fixed in V1.0.4.128
  13. Upgrade

    Upgrade R6700v3 (EoS) Nighthawk AC1750 Smart WiFi Dual Band Gigabit Router to a version that resolves this vulnerability.

    Fixed in V1.0.4.128
  14. Upgrade

    Upgrade R6900P (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router to a version that resolves this vulnerability.

    Fixed in V1.3.3.152
  15. Upgrade

    Upgrade R7000 (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router to a version that resolves this vulnerability.

    Fixed in V1.0.11.216
  16. Upgrade

    Upgrade R7000P (EoS) Nighthawk AC2300 Smart WiFi Dual Band Gigabit Router to a version that resolves this vulnerability.

    Fixed in V1.3.3.152
  17. Upgrade

    Upgrade R7960P (EoS) Nighthawk X6S AC3600 Tri-Band WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.4.4.92
  18. Upgrade

    Upgrade R8000P (EoS) Nighthawk X6S AC4000 Tri Band WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.4.4.92
  19. Upgrade

    Upgrade RAX20 (EoS) 4-Stream AX1800 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.18.144
  20. Upgrade

    Upgrade RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.118
  21. Upgrade

    Upgrade RAX40v2 Nighthawk AX4 4-Stream WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.118
  22. Upgrade

    Upgrade RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.118
  23. Upgrade

    Upgrade RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.118
  24. Upgrade

    Upgrade RAX43 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.120
  25. Upgrade

    Upgrade RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.118
  26. Upgrade

    Upgrade RAX48 Nighthawk AX6 6-Stream AX5200 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.118
  27. Upgrade

    Upgrade RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.120
  28. Upgrade

    Upgrade RAX50S Nighthawk AX6 6-Stream AX5400 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.120
  29. Upgrade

    Upgrade RAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Router to a version that resolves this vulnerability.

    Fixed in V1.0.10.86
  30. Upgrade

    Upgrade RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router to a version that resolves this vulnerability.

    Fixed in V1.0.10.86
  31. Upgrade

    Upgrade XR1000 Nighthawk WiFi 6 Pro Gaming Router to a version that resolves this vulnerability.

    Fixed in V1.0.0.68
  32. Remove

    Remove R8500 (EoS) Nighthawk X8 AC5300 Smart WiFi Router from your environment.

    Retire the device (EoS) because no security updates are planned; replace/upgrade to a newer NETGEAR device for continued security support.

Event History

Jun 9, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software
Nov 5, 58514
Event
via FIRST·09:59 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9210?

CVE-2026-9210 has a medium severity rating of 4.9 according to the CVSS.

2

How do I fix CVE-2026-9210?

To fix CVE-2026-9210, update the router's firmware to the latest version if automatic updates are not enabled.

3

What type of vulnerability is CVE-2026-9210?

CVE-2026-9210 is classified as an input validation vulnerability.

4

Who is affected by CVE-2026-9210?

CVE-2026-9210 affects certain NETGEAR router models when authenticated administrators are connected to the local network.

5

What is the risk associated with CVE-2026-9210?

CVE-2026-9210 poses a risk of unauthorized modification of router software and functionality by authenticated administrators.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203