Vulnerability Intelligence Report
Insufficient authentication and input validation in certain NETGEAR products
CVE-2026-9212
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
No Active Exploit Signals
CVSS Base Score
5.6
MEDIUM
EPSS Probability:0.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-306 ↗CWE-306 Missing authentication for critical function
CWE-20 ↗CWE-20 Improper input validation
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| NETGEAR | LBR1020 | 0 < V2.6.4.60 (affected) |
| NETGEAR | LBR20 | 0 < V2.7.6.8 (affected) |
| NETGEAR | R6700AX | 0 <= * (affected) |
| NETGEAR | R7800 | 0 < V1.0.4.96 (affected) |
| NETGEAR | R9000 | 0 < V1.0.6.46 (affected) |
| NETGEAR | RAX10 | 0 < V1.0.5.50 (affected) |
| NETGEAR | RAX10v2 | 0 < V1.0.5.50 (affected) |
| NETGEAR | RAX120 | 0 < V1.2.10.56 (affected) |
| NETGEAR | RAX120v1 | 0 < V1.2.10.56 (affected) |
| NETGEAR | RAX120v2 | 0 < V1.2.10.56 (affected) |
| NETGEAR | RAX36S | 0 < V1.0.5.50 (affected) |
| NETGEAR | RAX70 | 0 < V1.0.19.172 (affected) |
| NETGEAR | RAX78 | 0 < V1.0.19.172 (affected) |
| NETGEAR | RBR10 | 0 <= 2.7.6.6 (affected) |
| NETGEAR | RBR20 | 0 <= 2.7.6.6 (affected) |
| NETGEAR | RBR350 | 0 < V4.4.2.1 (affected) |
| NETGEAR | RBR40 | 0 <= 2.7.6.6 (affected) |
| NETGEAR | RBR50 | 0 <= 2.7.6.6 (affected) |
| NETGEAR | RBS10 | 0 <= 2.7.6.6 (affected) |
| NETGEAR | RBS20 | 0 <= 2.7.6.6 (affected) |
| NETGEAR | RBS350 | 0 < V4.4.2.1 (affected) |
| NETGEAR | RBS40 | 0 <= 2.7.6.6 (affected) |
| NETGEAR | RBS50 | 0 <= 2.7.6.6 (affected) |
| NETGEAR | XR450 | 0 < V2.3.3.136 (affected) |
| NETGEAR | XR500 | 0 < v2.3.3.136 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.270%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | NETGEAR · Vendor · USA |
| Reserved | 2026-05-21T17:29:04 |
| Published | 2026-06-09T15:50:53 |
| Patch Date | 2026-06-09 |
| Last Updated | 2026-06-11T05:03:05 |
Community Chatter & Buzz