CVE-2026-9212: Insufficient authentication and input validation in certain NETGEAR products

Published Jun 9, 2026
·
Updated

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

Affected Software

46 affected components
All of the following
Netgear Lbr1020 Firmware<2.6.4.60
Netgear LBR1020
All of the following
Netgear Lbr20 Firmware<2.7.6.8
Netgear LBR20
All of the following
Netgear R6700ax Firmware
Netgear R6700AX
All of the following
Netgear R7800 firmware<1.0.4.96
Netgear R7800
All of the following
Netgear R9000 Firmware<1.0.6.46
Netgear R9000
All of the following
Netgear Rax10 Firmware<1.0.5.50
Netgear RAX10
All of the following
Netgear Rax120 Firmware<1.2.10.56
Any of the following
Netgear RAX120
Netgear RAX120=1.0
Netgear RAX120=2.0
All of the following
Netgear Rax36s Firmware<1.0.5.50
Netgear Rax36s
All of the following
Netgear Rax70 Firmware<1.0.19.172
Netgear RAX70
All of the following
Netgear Rax78 Firmware<1.0.19.172
Netgear RAX78
All of the following
Netgear Rbr10 Firmware
Netgear RBR10
All of the following
Netgear Rbr20 Firmware
Netgear RBR20
All of the following
Netgear Rbr350 Firmware<4.4.2.1
Netgear RBR350
All of the following
Netgear Rbr40 Firmware
Netgear RBR40
All of the following
Netgear Rbr50 Firmware
Netgear RBR50
All of the following
Netgear Rbs10 Firmware
Netgear RBS10
All of the following
Netgear Rbs20 Firmware
Netgear RBS20
All of the following
Netgear Rbs350 Firmware<4.4.2.1
Netgear RBS350
All of the following
Netgear Rbs40 Firmware
Netgear RBS40
All of the following
Netgear Rbs50 Firmware
Netgear RBS50
All of the following
Netgear Xr450 Firmware<2.3.3.136
Netgear XR450
All of the following
Netgear Xr500 Firmware<2.3.3.136
Netgear XR500

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade NETGEAR LBR1020 (Orbi 4GX AC1200 Dual-Band Mesh WiFi Router V2.6.4.60) to a version that resolves this vulnerability.

    Fixed in 2.6.4.60
  2. Upgrade

    Upgrade NETGEAR LBR20 (Orbi LTE Tri-band WiFi Router) to a version that resolves this vulnerability.

    Fixed in 2.7.6.8
  3. Upgrade

    Upgrade NETGEAR R6700AX (4-Stream AX1800 WiFi 6 Router) to a version that resolves this vulnerability.

    Fixed in EOS
  4. Upgrade

    Upgrade NETGEAR R7800 (Nighthawk X4S AC2600 Smart WiFi Router) to a version that resolves this vulnerability.

    Fixed in 1.0.4.96
  5. Upgrade

    Upgrade NETGEAR R9000 (Nighthawk X10 AD7200 Smart WiFi Router) to a version that resolves this vulnerability.

    Fixed in 1.0.6.46
  6. Upgrade

    Upgrade NETGEAR RAX10 (4-Stream AX1800 WiFi 6 Router) to a version that resolves this vulnerability.

    Fixed in 1.0.5.50
  7. Upgrade

    Upgrade NETGEAR RAX10v2 (4-Stream AX1800 WiFi 6 Router) to a version that resolves this vulnerability.

    Fixed in 1.0.5.50
  8. Upgrade

    Upgrade NETGEAR RAX120 (Nighthawk AX12 12-Stream WiFi Router) to a version that resolves this vulnerability.

    Fixed in 1.2.10.56
  9. Upgrade

    Upgrade NETGEAR RAX120v1 (Nighthawk AX12 12-Stream WiFi Router) to a version that resolves this vulnerability.

    Fixed in 1.2.10.56
  10. Upgrade

    Upgrade NETGEAR RAX120v2 (Nighthawk AX12 12-Stream AX6000 WiFi Router) to a version that resolves this vulnerability.

    Fixed in 1.2.10.56
  11. Upgrade

    Upgrade NETGEAR RAX36S (Nighthawk AX4 4-Stream AX3000 WiFi Router) to a version that resolves this vulnerability.

    Fixed in 1.0.5.50
  12. Upgrade

    Upgrade NETGEAR RAX70 (Nighthawk Tri-band AX8 8-Stream AX6600 WiFi 6 Router) to a version that resolves this vulnerability.

    Fixed in 1.0.19.172
  13. Upgrade

    Upgrade NETGEAR RAX78 (Nighthawk AX8 8-Stream AX6200 Tri-Band WiFi Router) to a version that resolves this vulnerability.

    Fixed in 1.0.19.172
  14. Upgrade

    Upgrade NETGEAR RBR10 (Orbi AC1200 Dual-Band Mesh WiFi Router) to a version that resolves this vulnerability.

    Fixed in EOS
  15. Upgrade

    Upgrade NETGEAR RBR20 (Orbi AC2200 Tri-band WiFi Router) to a version that resolves this vulnerability.

    Fixed in EOS
  16. Upgrade

    Upgrade NETGEAR RBR350 (Orbi AX1800 WiFi 6 Dual-band Mesh Router) to a version that resolves this vulnerability.

    Fixed in 4.4.2.1
  17. Upgrade

    Upgrade NETGEAR RBR40 (Orbi AC2200 Tri-band WiFi Router) to a version that resolves this vulnerability.

    Fixed in EOS
  18. Upgrade

    Upgrade NETGEAR RBR50 (Orbi AC3000 Tri-band WiFi Router) to a version that resolves this vulnerability.

    Fixed in EOS
  19. Upgrade

    Upgrade NETGEAR RBS10 (Orbi AC1200 Dual-Band Mesh WiFi Add-on Satellite) to a version that resolves this vulnerability.

    Fixed in EOS
  20. Upgrade

    Upgrade NETGEAR RBS20 (Orbi AC2200 Tri-band WiFi Add-on Satellite) to a version that resolves this vulnerability.

    Fixed in EOS
  21. Upgrade

    Upgrade NETGEAR RBS350 (Orbi AX1800 WiFi 6 Dual-band Mesh Add-on Satellite) to a version that resolves this vulnerability.

    Fixed in 4.4.2.1
  22. Upgrade

    Upgrade NETGEAR RBS40 (Orbi AC2200 Tri-band WiFi Add-on Satellite) to a version that resolves this vulnerability.

    Fixed in EOS
  23. Upgrade

    Upgrade NETGEAR RBS50 (Orbi AC3000 Tri-band WiFi Add-on Satellite) to a version that resolves this vulnerability.

    Fixed in EOS
  24. Upgrade

    Upgrade NETGEAR XR450 (Nighthawk Pro Gaming Router V2.3.3.136) to a version that resolves this vulnerability.

    Fixed in 2.3.3.136
  25. Upgrade

    Upgrade NETGEAR XR500 (Nighthawk Pro Gaming Router v2.3.3.136) to a version that resolves this vulnerability.

    Fixed in 2.3.3.136
  26. Compensating control

    For NETGEAR models marked (EoS) in the provided list (e.g., LBR1020, R6700AX, R7800, R9000, RAX10v2, RAX120v1, RBR10, RBR20, RBR40, RBR50, RBS10, RBS20, RBS40, RBS50), retire the devices and upgrade to newer NETGEAR hardware for continued security support.

Event History

Jun 9, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 6, 58514
Event
via FIRST·03:46 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9212?

CVE-2026-9212 has a medium severity rating of 5.6 according to the CVSS scoring system.

2

What types of products are affected by CVE-2026-9212?

CVE-2026-9212 affects certain NETGEAR products that have insufficient authentication and input validation.

3

How can I fix CVE-2026-9212?

To fix CVE-2026-9212, check your device's firmware version and update it to the latest version if it does not have automatic updates enabled.

4

What impact does CVE-2026-9212 have on my device?

CVE-2026-9212 allows users connected to the local network to execute commands that can impact the device's confidentiality and configurations.

5

Is there a risk of exploitation with CVE-2026-9212?

Yes, there is a risk of exploitation through insufficient authentication and input validation in NETGEAR devices affected by CVE-2026-9212.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203