NETGEAR Router Local Network Auth Bypass & Command Exec
CVE-2026-9212 Published on June 9, 2026

Insufficient authentication and input validation in certain NETGEAR products
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting product's confidentiality or change certain configurations.

NVD

Weakness Types

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


Affected Versions

NETGEAR LBR1020: NETGEAR LBR20: NETGEAR R6700AX: NETGEAR R7800: NETGEAR R9000: NETGEAR RAX10: NETGEAR RAX10v2: NETGEAR RAX120: NETGEAR RAX120v1: NETGEAR RAX120v2: NETGEAR RAX36S: NETGEAR RAX70: NETGEAR RAX78: NETGEAR RBR10: NETGEAR RBR20: NETGEAR RBR350: NETGEAR RBR40: NETGEAR RBR50: NETGEAR RBS10: NETGEAR RBS20: NETGEAR RBS350: NETGEAR RBS40: NETGEAR RBS50: NETGEAR XR450: NETGEAR XR500: