Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9216— Insufficient input validation vulnerability exists in certain NETGEAR RAX Models

Quick assessment

Affected
NETGEAR RAX30
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

列出的 NETGEAR RAX 系列型号中存在一个输入验证不足漏洞,允许具有网络访问权限(如拥有 WiFi 凭据)的邻近网络攻击者导致路由器管理界面崩溃。该漏洞不影响机密性或完整性。管理界面崩溃不会影响路由器核心服务(如 WiFi 网络)的可用性。

CVSS 3.5 · Low

Possible ATT&CK Techniques 1 AI

T1497 · Virtualization/Sandbox Evasion

Affected Version Matrix 5

VendorProduct Version RangeStatus
NETGEAR RAX30 < V1.0.9.92 affected
NETGEAR RAX35 < V1.0.10.72 affected
NETGEAR RAX38 < V1.0.6.106 affected
NETGEAR RAX40 < V1.0.6.106 affected
NETGEAR RAXE300 < V1.0.10.72 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-9216

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Insufficient input validation vulnerability exists in certain NETGEAR RAX Models
Source: CVE Program / CVE List V5
Vulnerability Description
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
NETGEAR RAX30 0 ~ V1.0.9.92 -
NETGEAR RAX35 0 ~ V1.0.10.72 -
NETGEAR RAX38 0 ~ V1.0.6.106 -
NETGEAR RAX40 0 ~ V1.0.6.106 -
NETGEAR RAXE300 0 ~ V1.0.10.72 -

II. Public POCs for CVE-2026-9216

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9216

登录查看更多情报信息。

Vendor Pages for CVE-2026-9216 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-9216

No comments yet


Leave a comment