CVE-2026-11739 vulnerability in Netgear Products
Published on August 11, 2026
Command injection vulnerability in some NETGEAR Nighthawk devices
A command injection vulnerability in certain affected NETGEAR Nighthawk
devices allows a network-adjacent attacker with the ability to intercept
and modify local network traffic (attacker in the middle) to compromise
the confidentiality and integrity of the affected device.
Vulnerability Analysis
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-11739 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2026-11739
Want to know whenever a new CVE is published for Netgear products? stack.watch will email you.
Affected Versions
NETGEAR MR60:- Before V1.1.8.142 is affected.
- Before V1.0.4.48 is affected.
- Before V1.0.2.46 is affected.
- Before V1.1.8.142 is affected.
- Before V1.0.4.48 is affected.
- Before V1.0.2.46 is affected.
- Before V1.0.17.142 is affected.
- Before V1.0.11.148 is affected.
- Before V1.0.17.142 is affected.
- Before V1.0.17.142 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.0.17.142 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.1.6.36 is affected.
- Before V1.0.11.148 is affected.
- Before V1.2.14.110 is affected.
- Before V1.0.9.6 is affected.
- Before V1.1.0.22 is affected.
- Before V1.1.0.22 is affected.