ZeroHour

CVE-2026-9216

CVSS 4.0
1.2 low
EPSS
<1%p13
Published
()
Modified
Description

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.

Vendors
netgear
Products
rax30 firmware, rax35 firmware, rax38 firmware, rax40 firmware, raxe300 firmware
Weakness
CWE-121
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:D/RE:L/U:Amber

In the news

No ingested article mentions this CVE yet.