Vulnerability Intelligence Report
Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers
CVE-2026-11814
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
No Active Exploit Signals
CVSS Base Score
4.9
MEDIUM
EPSS Probability:0.83%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-295 ↗CWE-295 Improper certificate validation
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| NETGEAR | BE9300 | 0 < V1.0.1.84 (affected) |
| NETGEAR | MR60 | 0 < V1.1.8.142 (affected) |
| NETGEAR | MS60 | 0 < V1.1.8.142 (affected) |
| NETGEAR | R6700AX | 0 < V1.0.18.164 (affected) |
| NETGEAR | RAX10 | 0 < V1.0.5.50 (affected) |
| NETGEAR | RAX120 | 0 < V1.2.10.56 (affected) |
| NETGEAR | RAX120v2 | 0 < V1.2.10.56 (affected) |
| NETGEAR | RAX20 | 0 < V1.0.17.142 (affected) |
| NETGEAR | RAX28 | 0 < V1.0.14.108 (affected) |
| NETGEAR | RAX29 | 0 < V1.0.14.108 (affected) |
| NETGEAR | RAX30 | 0 < V1.0.14.108 (affected) |
| NETGEAR | RAX36S | 0 < V1.0.5.50 (affected) |
| NETGEAR | RAX43 | 0 < V1.0.17.142 (affected) |
| NETGEAR | RAX45 | 0 < V1.0.17.142 (affected) |
| NETGEAR | RAX50 | 0 < V1.0.17.142 (affected) |
| NETGEAR | RAX70 | 0 < V1.0.19.172 (affected) |
| NETGEAR | RBR760 | 0 < V6.3.8.11 (affected) |
| NETGEAR | RBS760 | 0 < V6.3.8.11 (affected) |
| NETGEAR | RS100 | 0 < V1.0.1.80 (affected) |
| NETGEAR | RS200 | 0 < V1.0.1.90 (affected) |
| NETGEAR | RS280 | 0 < V1.0.1.90 (affected) |
| NETGEAR | RS300 | 0 < V1.0.1.90 (affected) |
| NETGEAR | RS500 | 0 < V1.0.1.90 (affected) |
| NETGEAR | RS600 | 0 < V1.0.1.90 (affected) |
| NETGEAR | RS70 | 0 < V1.0.1.80 (affected) |
| NETGEAR | RS90 | 0 < V1.0.1.80 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.825%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | NETGEAR · Vendor · USA |
| Reserved | 2026-06-09T15:57:56 |
| Published | 2026-08-11T15:06:08 |
| Patch Date | 2026-08-11 |
| Last Updated | 2026-08-12T14:42:32 |
Community Chatter & Buzz