CVE-2026-11814 vulnerability in Netgear Products
Published on August 11, 2026
Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Vulnerability Analysis
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2026-11814
Want to know whenever a new CVE is published for Netgear products? stack.watch will email you.
Affected Versions
NETGEAR BE9300:- Before V1.0.1.84 is affected.
- Before V1.1.8.142 is affected.
- Before V1.1.8.142 is affected.
- Before V1.0.18.164 is affected.
- Before V1.0.5.50 is affected.
- Before V1.2.10.56 is affected.
- Before V1.2.10.56 is affected.
- Before V1.0.17.142 is affected.
- Before V1.0.14.108 is affected.
- Before V1.0.14.108 is affected.
- Before V1.0.14.108 is affected.
- Before V1.0.5.50 is affected.
- Before V1.0.17.142 is affected.
- Before V1.0.17.142 is affected.
- Before V1.0.17.142 is affected.
- Before V1.0.19.172 is affected.
- Before V6.3.8.11 is affected.
- Before V6.3.8.11 is affected.
- Before V1.0.1.80 is affected.
- Before V1.0.1.90 is affected.
- Before V1.0.1.90 is affected.
- Before V1.0.1.90 is affected.
- Before V1.0.1.90 is affected.
- Before V1.0.1.90 is affected.
- Before V1.0.1.80 is affected.
- Before V1.0.1.80 is affected.