ZeroHour

CVE-2026-11739

CVSS 4.0
4.9 medium
EPSS
1%p63
Published
()
Modified
Description

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.

Vendors
netgear
Products
ms90 firmware, rax20 firmware, rax200 firmware, rax35 firmware, rax35v2 firmware, rax41 firmware, rax41v2 firmware, rax42 firmware, rax42v2 firmware, rax43 firmware, rax43v2 firmware, rax45 firmware
Weakness
CWE-78
Vector
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber

In the news

No ingested article mentions this CVE yet.