NETGEAR Router Auth Priv Esc via Input Validation
CVE-2026-11737 Published on August 11, 2026
Some NETGEAR Nighthawk devices allow administrators to tamper with the device
Insufficient input validation vulnerability in the listed
NETGEAR models allows authenticated administrators connected to the
local network to make unauthorized modification to the device software and
functionality.
Vulnerability Analysis
Weakness Type
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Products Associated with CVE-2026-11737
Want to know whenever a new CVE is published for Netgear products? stack.watch will email you.
Affected Versions
NETGEAR RAX20:- Before V1.0.18.144 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.0.17.142 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.