Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9212— Insufficient authentication and input validation in certain NETGEAR products

AI Predicted 9.0 Difficulty: Easy EPSS 0.27% · P19

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 25

VendorProductVersion RangeStatus
NETGEARLBR1020< V2.6.4.60affected
NETGEARLBR20< V2.7.6.8affected
NETGEARR6700AX≤ *affected
NETGEARR7800< V1.0.4.96affected
NETGEARR9000< V1.0.6.46affected
NETGEARRAX10< V1.0.5.50affected
NETGEARRAX10v2< V1.0.5.50affected
NETGEARRAX120< V1.2.10.56affected
NETGEARRAX120v1< V1.2.10.56affected
NETGEARRAX120v2< V1.2.10.56affected
NETGEARRAX36S< V1.0.5.50affected
NETGEARRAX70< V1.0.19.172affected
NETGEARRAX78< V1.0.19.172affected
NETGEARRBR10≤ 2.7.6.6affected
NETGEARRBR20≤ 2.7.6.6affected
NETGEARRBR350< V4.4.2.1affected
NETGEARRBR40≤ 2.7.6.6affected
NETGEARRBR50≤ 2.7.6.6affected
NETGEARRBS10≤ 2.7.6.6affected
NETGEARRBS20≤ 2.7.6.6affected
NETGEARRBS350< V4.4.2.1affected
NETGEARRBS40≤ 2.7.6.6affected
NETGEARRBS50≤ 2.7.6.6affected
NETGEARXR450< V2.3.3.136affected
NETGEARXR500< v2.3.3.136affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9212

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Insufficient authentication and input validation in certain NETGEAR products
Source: CVE Program / CVE List V5
Vulnerability Description
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:U
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
NETGEAR多款产品 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NETGEAR RAX120等都是美国网件(NETGEAR)公司的一款无线路由器。 NETGEAR多款产品存在输入验证错误漏洞,该漏洞源于身份验证和输入验证不足,可能导致本地网络连接的用户执行影响产品机密性的命令或更改某些配置。以下产品受到影响:lbr1020、lbr20、r6700ax、r7800、r9000、rax10、rax120、rax120v2、rax36s、rax70、rax78、rbr10、rbr20、rbr350、rbr40、rbr50、rbs10、rbs20、rbs350、rbs40、r
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
NETGEARLBR1020 0 ~ V2.6.4.60 -
NETGEARLBR20 0 ~ V2.7.6.8 -
NETGEARR6700AX 0 ~ * -
NETGEARR7800 0 ~ V1.0.4.96 -
NETGEARR9000 0 ~ V1.0.6.46 -
NETGEARRAX10 0 ~ V1.0.5.50 -
NETGEARRAX10v2 0 ~ V1.0.5.50 -
NETGEARRAX120 0 ~ V1.2.10.56 -
NETGEARRAX120v1 0 ~ V1.2.10.56 -
NETGEARRAX120v2 0 ~ V1.2.10.56 -
NETGEARRAX36S 0 ~ V1.0.5.50 -
NETGEARRAX70 0 ~ V1.0.19.172 -
NETGEARRAX78 0 ~ V1.0.19.172 -
NETGEARRBR10 0 ~ 2.7.6.6 -
NETGEARRBR20 0 ~ 2.7.6.6 -
NETGEARRBR350 0 ~ V4.4.2.1 -
NETGEARRBR40 0 ~ 2.7.6.6 -
NETGEARRBR50 0 ~ 2.7.6.6 -
NETGEARRBS10 0 ~ 2.7.6.6 -
NETGEARRBS20 0 ~ 2.7.6.6 -
NETGEARRBS350 0 ~ V4.4.2.1 -
NETGEARRBS40 0 ~ 2.7.6.6 -
NETGEARRBS50 0 ~ 2.7.6.6 -
NETGEARXR450 0 ~ V2.3.3.136 -
NETGEARXR500 0 ~ v2.3.3.136 -

II. Public POCs for CVE-2026-9212

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9212

登录查看更多情报信息。

Vendor Pages for CVE-2026-9212 (23)

Same Patch Batch · NETGEAR · 2026-06-09 · 17 CVEs total

CVE-2026-0412Insufficient input validation vulnerability in NETGEAR JR6150 Web UI
CVE-2026-0414Insufficient Input Validation Allows Unauthorized Modification of Router Software in certa
CVE-2026-0420Missing TLS certificate validation in NETGEAR's ReadyCloud client app
CVE-2026-0415Insufficient input validation vulnerability in certain Orbi routers
CVE-2026-0417Insufficient input validation in certain NETGEAR routers
CVE-2026-0418Certain NETGEAR devices allow administrators to tamper with system
CVE-2026-0416Improper input validation in certain NETGEAR routers allows unauthorized modification of p
CVE-2026-0410Insufficient input validation in certain NETGEAR routers
CVE-2026-0409Netgear Orbi 370 Series Remote Code Execution vulnerability
CVE-2026-0411A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi Satellites
CVE-2026-0419Insufficient input validation vulnerability in NETGEAR JR6150
CVE-2026-0413Buffer overflow vulnerability in certain NETGEAR Nighthawk routers
CVE-2026-3088Unauthenticated users can disrupt router operation
CVE-2026-9210Certain NETGEAR routers allow authenticated administrators to gain unintended control of t
CVE-2026-9213Insufficient input validation in certain NETGEAR routers
CVE-2026-9211Certain NETGEAR routers allow unauthenticated users to gain control of the router

IV. Related Vulnerabilities

V. Comments for CVE-2026-9212

No comments yet


Leave a comment