CVE-2026-9212: Insufficient authentication and input validation in certain NETGEAR products
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR LBR1020 (Orbi 4GX AC1200 Dual-Band Mesh WiFi Router V2.6.4.60)to a version that resolves this vulnerability.Fixed in 2.6.4.60 - Upgrade
Upgrade
NETGEAR LBR20 (Orbi LTE Tri-band WiFi Router)to a version that resolves this vulnerability.Fixed in 2.7.6.8 - Upgrade
Upgrade
NETGEAR R6700AX (4-Stream AX1800 WiFi 6 Router)to a version that resolves this vulnerability.Fixed in EOS - Upgrade
Upgrade
NETGEAR R7800 (Nighthawk X4S AC2600 Smart WiFi Router)to a version that resolves this vulnerability.Fixed in 1.0.4.96 - Upgrade
Upgrade
NETGEAR R9000 (Nighthawk X10 AD7200 Smart WiFi Router)to a version that resolves this vulnerability.Fixed in 1.0.6.46 - Upgrade
Upgrade
NETGEAR RAX10 (4-Stream AX1800 WiFi 6 Router)to a version that resolves this vulnerability.Fixed in 1.0.5.50 - Upgrade
Upgrade
NETGEAR RAX10v2 (4-Stream AX1800 WiFi 6 Router)to a version that resolves this vulnerability.Fixed in 1.0.5.50 - Upgrade
Upgrade
NETGEAR RAX120 (Nighthawk AX12 12-Stream WiFi Router)to a version that resolves this vulnerability.Fixed in 1.2.10.56 - Upgrade
Upgrade
NETGEAR RAX120v1 (Nighthawk AX12 12-Stream WiFi Router)to a version that resolves this vulnerability.Fixed in 1.2.10.56 - Upgrade
Upgrade
NETGEAR RAX120v2 (Nighthawk AX12 12-Stream AX6000 WiFi Router)to a version that resolves this vulnerability.Fixed in 1.2.10.56 - Upgrade
Upgrade
NETGEAR RAX36S (Nighthawk AX4 4-Stream AX3000 WiFi Router)to a version that resolves this vulnerability.Fixed in 1.0.5.50 - Upgrade
Upgrade
NETGEAR RAX70 (Nighthawk Tri-band AX8 8-Stream AX6600 WiFi 6 Router)to a version that resolves this vulnerability.Fixed in 1.0.19.172 - Upgrade
Upgrade
NETGEAR RAX78 (Nighthawk AX8 8-Stream AX6200 Tri-Band WiFi Router)to a version that resolves this vulnerability.Fixed in 1.0.19.172 - Upgrade
Upgrade
NETGEAR RBR10 (Orbi AC1200 Dual-Band Mesh WiFi Router)to a version that resolves this vulnerability.Fixed in EOS - Upgrade
Upgrade
NETGEAR RBR20 (Orbi AC2200 Tri-band WiFi Router)to a version that resolves this vulnerability.Fixed in EOS - Upgrade
Upgrade
NETGEAR RBR350 (Orbi AX1800 WiFi 6 Dual-band Mesh Router)to a version that resolves this vulnerability.Fixed in 4.4.2.1 - Upgrade
Upgrade
NETGEAR RBR40 (Orbi AC2200 Tri-band WiFi Router)to a version that resolves this vulnerability.Fixed in EOS - Upgrade
Upgrade
NETGEAR RBR50 (Orbi AC3000 Tri-band WiFi Router)to a version that resolves this vulnerability.Fixed in EOS - Upgrade
Upgrade
NETGEAR RBS10 (Orbi AC1200 Dual-Band Mesh WiFi Add-on Satellite)to a version that resolves this vulnerability.Fixed in EOS - Upgrade
Upgrade
NETGEAR RBS20 (Orbi AC2200 Tri-band WiFi Add-on Satellite)to a version that resolves this vulnerability.Fixed in EOS - Upgrade
Upgrade
NETGEAR RBS350 (Orbi AX1800 WiFi 6 Dual-band Mesh Add-on Satellite)to a version that resolves this vulnerability.Fixed in 4.4.2.1 - Upgrade
Upgrade
NETGEAR RBS40 (Orbi AC2200 Tri-band WiFi Add-on Satellite)to a version that resolves this vulnerability.Fixed in EOS - Upgrade
Upgrade
NETGEAR RBS50 (Orbi AC3000 Tri-band WiFi Add-on Satellite)to a version that resolves this vulnerability.Fixed in EOS - Upgrade
Upgrade
NETGEAR XR450 (Nighthawk Pro Gaming Router V2.3.3.136)to a version that resolves this vulnerability.Fixed in 2.3.3.136 - Upgrade
Upgrade
NETGEAR XR500 (Nighthawk Pro Gaming Router v2.3.3.136)to a version that resolves this vulnerability.Fixed in 2.3.3.136 - Compensating control
For NETGEAR models marked (EoS) in the provided list (e.g., LBR1020, R6700AX, R7800, R9000, RAX10v2, RAX120v1, RBR10, RBR20, RBR40, RBR50, RBS10, RBS20, RBS40, RBS50), retire the devices and upgrade to newer NETGEAR hardware for continued security support.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9212?
CVE-2026-9212 has a medium severity rating of 5.6 according to the CVSS scoring system.
What types of products are affected by CVE-2026-9212?
CVE-2026-9212 affects certain NETGEAR products that have insufficient authentication and input validation.
How can I fix CVE-2026-9212?
To fix CVE-2026-9212, check your device's firmware version and update it to the latest version if it does not have automatic updates enabled.
What impact does CVE-2026-9212 have on my device?
CVE-2026-9212 allows users connected to the local network to execute commands that can impact the device's confidentiality and configurations.
Is there a risk of exploitation with CVE-2026-9212?
Yes, there is a risk of exploitation through insufficient authentication and input validation in NETGEAR devices affected by CVE-2026-9212.