Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-11814— Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers

Quick assessment

Affected
NETGEAR BE9300
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

NETGEAR BE9300是美国NETGEAR公司的一款无线路由器。 NETGEAR BE9300存在加密问题漏洞,该漏洞源于命令注入,可能导致网络邻近的攻击者通过拦截和修改本地网络流量的中间人攻击破坏受影响设备的机密性和完整性。

CVSS 4.9 · Medium EPSS 0.91% · P59

Affected Version Matrix 26

VendorProduct Version RangeStatus
NETGEAR BE9300 < V1.0.1.84 affected
NETGEAR MR60 < V1.1.8.142 affected
NETGEAR MS60 < V1.1.8.142 affected
NETGEAR R6700AX < V1.0.18.164 affected
NETGEAR RAX10 < V1.0.5.50 affected
NETGEAR RAX120 < V1.2.10.56 affected
NETGEAR RAX120v2 < V1.2.10.56 affected
NETGEAR RAX20 < V1.0.17.142 affected
NETGEAR RAX28 < V1.0.14.108 affected
NETGEAR RAX29 < V1.0.14.108 affected
NETGEAR RAX30 < V1.0.14.108 affected
NETGEAR RAX36S < V1.0.5.50 affected
NETGEAR RAX43 < V1.0.17.142 affected
NETGEAR RAX45 < V1.0.17.142 affected
NETGEAR RAX50 < V1.0.17.142 affected
NETGEAR RAX70 < V1.0.19.172 affected
NETGEAR RBR760 < V6.3.8.11 affected
NETGEAR RBS760 < V6.3.8.11 affected
NETGEAR RS100 < V1.0.1.80 affected
NETGEAR RS200 < V1.0.1.90 affected
NETGEAR RS280 < V1.0.1.90 affected
NETGEAR RS300 < V1.0.1.90 affected
NETGEAR RS500 < V1.0.1.90 affected
NETGEAR RS600 < V1.0.1.90 affected
NETGEAR RS70 < V1.0.1.80 affected
NETGEAR RS90 < V1.0.1.80 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-11814

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers
Source: CVE Program / CVE List V5
Vulnerability Description
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
NETGEAR BE9300 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NETGEAR BE9300是美国NETGEAR公司的一款无线路由器。 NETGEAR BE9300存在加密问题漏洞,该漏洞源于命令注入,可能导致网络邻近的攻击者通过拦截和修改本地网络流量的中间人攻击破坏受影响设备的机密性和完整性。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
NETGEAR BE9300 0 ~ V1.0.1.84 -
NETGEAR MR60 0 ~ V1.1.8.142 -
NETGEAR MS60 0 ~ V1.1.8.142 -
NETGEAR R6700AX 0 ~ V1.0.18.164 -
NETGEAR RAX10 0 ~ V1.0.5.50 -
NETGEAR RAX120 0 ~ V1.2.10.56 -
NETGEAR RAX120v2 0 ~ V1.2.10.56 -
NETGEAR RAX20 0 ~ V1.0.17.142 -
NETGEAR RAX28 0 ~ V1.0.14.108 -
NETGEAR RAX29 0 ~ V1.0.14.108 -
NETGEAR RAX30 0 ~ V1.0.14.108 -
NETGEAR RAX36S 0 ~ V1.0.5.50 -
NETGEAR RAX43 0 ~ V1.0.17.142 -
NETGEAR RAX45 0 ~ V1.0.17.142 -
NETGEAR RAX50 0 ~ V1.0.17.142 -
NETGEAR RAX70 0 ~ V1.0.19.172 -
NETGEAR RBR760 0 ~ V6.3.8.11 -
NETGEAR RBS760 0 ~ V6.3.8.11 -
NETGEAR RS100 0 ~ V1.0.1.80 -
NETGEAR RS200 0 ~ V1.0.1.90 -
NETGEAR RS280 0 ~ V1.0.1.90 -
NETGEAR RS300 0 ~ V1.0.1.90 -
NETGEAR RS500 0 ~ V1.0.1.90 -
NETGEAR RS600 0 ~ V1.0.1.90 -
NETGEAR RS70 0 ~ V1.0.1.80 -
NETGEAR RS90 0 ~ V1.0.1.80 -

II. Public POCs for CVE-2026-11814

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-11814

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-11814 (1)

Vendor Pages for CVE-2026-11814 (26)

Same Patch Batch · NETGEAR · 2026-08-11 · 9 CVEs total

CVE-2026-11739 4.9 MEDIUM Command injection vulnerability in some NETGEAR Nighthawk devices
CVE-2026-11737 4.3 MEDIUM Some NETGEAR Nighthawk devices allow administrators to tamper with the device
CVE-2026-11738 4.3 MEDIUM Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators t
CVE-2026-9214 4.3 MEDIUM Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with
CVE-2026-11735 1.9 LOW Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models
CVE-2026-11736 1.9 LOW Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers
CVE-2026-11734 1.1 LOW Device administrator can interrupt the normal operation of some NETGEAR Nighthawk devices.
CVE-2026-11733 1.1 LOW Buffer overflow vulnerability in some NETGEAR Nighthawk routers

IV. Related Vulnerabilities

V. Comments for CVE-2026-11814

No comments yet


Leave a comment