NETGEAR router admin privilege escalation via input validation
CVE-2026-11738 Published on August 11, 2026
Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Vulnerability Analysis
Weakness Type
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Products Associated with CVE-2026-11738
Want to know whenever a new CVE is published for Netgear products? stack.watch will email you.
Affected Versions
NETGEAR R7000:- Before * is affected.
- Before V1.2.14.114 is affected.
- Before V1.0.7.66 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.