CVE-2026-9213: Insufficient input validation in certain NETGEAR routers
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR MR70 Nighthawk Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.4.48 - Upgrade
Upgrade
NETGEAR MS70 Nighthawk Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.0.4.48 - Upgrade
Upgrade
NETGEAR RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.2.14.114 - Upgrade
Upgrade
NETGEAR XR1000 Nighthawk WiFi 6 Pro Gaming Routerto a version that resolves this vulnerability.Fixed in V1.0.2.86
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9213?
The severity of CVE-2026-9213 is medium with a CVSS score of 6.9.
How do I fix CVE-2026-9213?
To fix CVE-2026-9213, ensure your NETGEAR router firmware is updated to the latest version.
What devices are affected by CVE-2026-9213?
CVE-2026-9213 affects certain NETGEAR gaming routers, particularly the Nighthawk series.
What kind of vulnerability is CVE-2026-9213?
CVE-2026-9213 is classified as an insufficient input validation vulnerability.
Can CVE-2026-9213 be exploited remotely?
Yes, CVE-2026-9213 can be exploited remotely by attackers intercepting and tampering with traffic.