ZeroHour

CVE-2026-11814

CVSS 4.0
4.9 medium
EPSS
<1%p58
Published
()
Modified
Description

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.

Vendors
netgear
Products
be9300 firmware, mr60 firmware, ms60 firmware, r6700ax firmware, rax10 firmware, rax120 firmware, rax120v2 firmware, rax20 firmware, rax28 firmware, rax29 firmware, rax30 firmware, rax36s firmware
Weakness
CWE-295, CWE-77
Vector
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber

In the news

No ingested article mentions this CVE yet.