CVE-2026-9210: Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR firmware (listed models)to a version that resolves this vulnerability.Fixed in latest - Upgrade
Upgrade
EX3700 AC750 WiFi Range Extender Essentials Edition V1.0.0.100to a version that resolves this vulnerability.Fixed in V1.0.0.100 - Upgrade
Upgrade
EX3800 (EoS) AC750 WiFi Range Extender Essentials Edition V1.0.0.100to a version that resolves this vulnerability.Fixed in V1.0.0.100 - Upgrade
Upgrade
EX6120 AC1200 Dual Band WiFi Range Extenderto a version that resolves this vulnerability.Fixed in V1.0.0.72 - Upgrade
Upgrade
EX6130 AC1200 WiFi Range Extenderto a version that resolves this vulnerability.Fixed in V1.0.0.54 - Upgrade
Upgrade
MR60 Nighthawk Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.1.7.132 - Upgrade
Upgrade
MR70 Nighthawk Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.3.28 - Upgrade
Upgrade
MR80 Nighthawk Tri-band Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.1.7.14 - Upgrade
Upgrade
MS60 Nighthawk Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.1.7.132 - Upgrade
Upgrade
MS70 Nighthawk Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.0.3.28 - Upgrade
Upgrade
MS80 Nighthawk Tri-band Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.1.7.14 - Upgrade
Upgrade
R6400v2 (EoS) AC1750 Smart WiFi Router 802.11ac Dual Band Gigabitto a version that resolves this vulnerability.Fixed in V1.0.4.128 - Upgrade
Upgrade
R6700v3 (EoS) Nighthawk AC1750 Smart WiFi Dual Band Gigabit Routerto a version that resolves this vulnerability.Fixed in V1.0.4.128 - Upgrade
Upgrade
R6900P (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Routerto a version that resolves this vulnerability.Fixed in V1.3.3.152 - Upgrade
Upgrade
R7000 (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Routerto a version that resolves this vulnerability.Fixed in V1.0.11.216 - Upgrade
Upgrade
R7000P (EoS) Nighthawk AC2300 Smart WiFi Dual Band Gigabit Routerto a version that resolves this vulnerability.Fixed in V1.3.3.152 - Upgrade
Upgrade
R7960P (EoS) Nighthawk X6S AC3600 Tri-Band WiFi Routerto a version that resolves this vulnerability.Fixed in V1.4.4.92 - Upgrade
Upgrade
R8000P (EoS) Nighthawk X6S AC4000 Tri Band WiFi Routerto a version that resolves this vulnerability.Fixed in V1.4.4.92 - Upgrade
Upgrade
RAX20 (EoS) 4-Stream AX1800 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.18.144 - Upgrade
Upgrade
RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.12.118 - Upgrade
Upgrade
RAX40v2 Nighthawk AX4 4-Stream WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.12.118 - Upgrade
Upgrade
RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.12.118 - Upgrade
Upgrade
RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.12.118 - Upgrade
Upgrade
RAX43 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.12.120 - Upgrade
Upgrade
RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.12.118 - Upgrade
Upgrade
RAX48 Nighthawk AX6 6-Stream AX5200 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.12.118 - Upgrade
Upgrade
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.12.120 - Upgrade
Upgrade
RAX50S Nighthawk AX6 6-Stream AX5400 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.12.120 - Upgrade
Upgrade
RAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.0.10.86 - Upgrade
Upgrade
RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.0.10.86 - Upgrade
Upgrade
XR1000 Nighthawk WiFi 6 Pro Gaming Routerto a version that resolves this vulnerability.Fixed in V1.0.0.68 - Remove
Remove
R8500 (EoS) Nighthawk X8 AC5300 Smart WiFi Routerfrom your environment.Retire the device (EoS) because no security updates are planned; replace/upgrade to a newer NETGEAR device for continued security support.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9210?
CVE-2026-9210 has a medium severity rating of 4.9 according to the CVSS.
How do I fix CVE-2026-9210?
To fix CVE-2026-9210, update the router's firmware to the latest version if automatic updates are not enabled.
What type of vulnerability is CVE-2026-9210?
CVE-2026-9210 is classified as an input validation vulnerability.
Who is affected by CVE-2026-9210?
CVE-2026-9210 affects certain NETGEAR router models when authenticated administrators are connected to the local network.
What is the risk associated with CVE-2026-9210?
CVE-2026-9210 poses a risk of unauthorized modification of router software and functionality by authenticated administrators.