CVE-2026-9211: Certain NETGEAR routers allow unauthenticated users to gain control of the router
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
netgear/CAX30 Nighthawk AX6 6-Stream WiFi 6 Cable Modem Router V2to a version that resolves this vulnerability.Fixed in 2.2.1.4 - Upgrade
Upgrade
netgear/RAX30 Nighthawk AX5 5-Stream AX2400 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in 1.0.10.94 - Upgrade
Upgrade
netgear/RAX5 4-Stream AX1600 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in 1.0.5.34 - Upgrade
Upgrade
netgear/RAXE300 Nighthawk AXE7800 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in 1.0.10.72
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9211?
CVE-2026-9211 has a medium severity rating of 5.2 on the CVSS scale.
How do I fix CVE-2026-9211?
To fix CVE-2026-9211, check the firmware version of your NETGEAR router and update it to the latest version if automatic updates are not enabled.
What type of devices are affected by CVE-2026-9211?
CVE-2026-9211 affects certain NETGEAR routers that allow unauthenticated users to gain control and modify settings.
What are the risks associated with CVE-2026-9211?
The risks associated with CVE-2026-9211 include unauthorized changes to router settings, compromising the security of the local network.
When was CVE-2026-9211 published?
CVE-2026-9211 was published on June 9, 2026.