ZeroHour

Vulnerabilities

1,276 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-9216
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi cr

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.

NVD description · AI analysis pending
1.2<1%
  • netgear rax30 firmware
  • netgear rax35 firmware
  • netgear rax38 firmware
  • +1 more
CVE-2026-9215
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router adm

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.

NVD description · AI analysis pending
1.8<1%
  • netgear xr1000 firmware
  • netgear xr1000v2 firmware
  • netgear xr500 firmware
CVE-2026-9214
+1 in the same advisory: …11735
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized

Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

NVD description · AI analysis pending
4.3
group max
<1%
  • netgear r7000 firmware
CVE-2026-11814
+1 in the same advisory: …11738
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.

NVD description · AI analysis pending
4.9
group max
<1%
  • netgear be9300 firmware
  • netgear mr60 firmware
  • netgear ms60 firmware
  • +1 more
CVE-2026-11739
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify loca

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.

NVD description · AI analysis pending
4.91%
  • netgear ms90 firmware
  • netgear rax20 firmware
  • netgear rax200 firmware
  • +1 more
CVE-2026-11737
+1 in the same advisory: …11736
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.

NVD description · AI analysis pending
4.3
group max
<1%
  • netgear rax20 firmware
  • netgear rax41 firmware
  • netgear rax41v2 firmware
  • +1 more
CVE-2026-11734
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.

A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.

NVD description · AI analysis pending
1.1<1%
  • netgear mr70 firmware
  • netgear mr90 firmware
  • netgear ms70 firmware
  • +1 more
CVE-2026-11733
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.

A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.

NVD description · AI analysis pending
1.1<1%
  • netgear rax41 firmware
  • netgear rax41v2 firmware
  • netgear rax42 firmware
  • +1 more
CVE-2026-9213
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Interne

A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.

NVD description · AI analysis pending
6.9<1%
  • netgear mr70 firmware
  • netgear ms70 firmware
  • netgear raxe500 firmware
  • +1 more
CVE-2026-9212
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the produ

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

NVD description · AI analysis pending
5.6<1%
  • netgear lbr1020 firmware
  • netgear lbr20 firmware
  • netgear r6700ax firmware
  • +1 more
CVE-2026-9211
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.

An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.

NVD description · AI analysis pending
5.2<1%
  • netgear cax30 firmware
  • netgear rax30 firmware
  • netgear rax5 firmware
  • +1 more
CVE-2026-9210
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

NVD description · AI analysis pending
4.9<1%
  • netgear ex3700 firmware
  • netgear ex3800 firmware
  • netgear ex6120 firmware
  • +1 more
CVE-2026-3088
+3 in the same advisory: …0415 …0414 …0411
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.

Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.

NVD description · AI analysis pending
4.9
group max
<1%
  • netgear rbe970 firmware
  • netgear rbe971 firmware
  • netgear rbr860 firmware
  • +1 more
CVE-2026-0420
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacke

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.

NVD description · AI analysis pending
4.6<1%
  • netgear rax120 firmware
  • netgear rax35 firmware
  • netgear rax38 firmware
  • +1 more
CVE-2026-0419
+1 in the same advisory: …0412
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Network

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.

NVD description · AI analysis pending
4.4
group max
<1%
  • netgear jr6150 firmware
CVE-2026-0418
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

NVD description · AI analysis pending
4.3<1%
  • netgear cbr750 firmware
  • netgear ex6120 firmware
  • netgear ex6130 firmware
  • +1 more
CVE-2026-0417
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the

Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

NVD description · AI analysis pending
4.3<1%
  • netgear mr60 firmware
  • netgear mr70 firmware
  • netgear mr80 firmware
  • +1 more
CVE-2026-0416
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to sub

An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.

NVD description · AI analysis pending
4.3<1%
  • netgear raxe450 firmware
  • netgear raxe500 firmware
CVE-2026-0409
+1 in the same advisory: …0413
A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on y

A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.

NVD description · AI analysis pending
4.8
group max
<1%
  • netgear rbe370 firmware
  • netgear rbe371 firmware
  • netgear rbe372 firmware
  • +1 more
CVE-2026-0410
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and function

Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.

NVD description · AI analysis pending
1.9<1%
  • netgear r7000 firmware
  • netgear rax20 firmware
  • netgear rax35v2 firmware
  • +1 more
CVE-2022-40619
+1 in the same advisory: …40620
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices.

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.

NVD description · AI analysis pending
7.72% PoC
  • netgear rbr20 firmware
  • netgear r6230 firmware
  • netgear r6260 firmware
  • +1 more
CVE-2026-0408
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of t

A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.

NVD description · AI analysis pending
6.1<1%
  • netgear ex2800 firmware
  • netgear ex3110 firmware
  • netgear ex5000 firmware
  • +1 more
CVE-2026-0407
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet

An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.

NVD description · AI analysis pending
6.1<1%
  • netgear ex5000 firmware
  • netgear ex3110 firmware
  • netgear ex6110 firmware
  • +1 more
CVE-2026-0406
An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections.

An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections.

NVD description · AI analysis pending
6.1<1%
  • netgear xr1000v2 firmware
CVE-2026-0405
An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

NVD description · AI analysis pending
6.1<1%
  • netgear cbr750 firmware
  • netgear nbr750 firmware
  • netgear rbe370 firmware
  • +1 more
CVE-2026-0404
An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

NVD description · AI analysis pending
4.81%
  • netgear rbr750 firmware
  • netgear rbr840 firmware
  • netgear rbr850 firmware
  • +1 more
CVE-2026-0403
An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

NVD description · AI analysis pending
1.1<1%
  • netgear rbe971 firmware
  • netgear rbe970 firmware
  • netgear rbr750 firmware
  • +1 more
CVE-2025-50526
+1 in the same advisory: …45493
Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

NVD description · AI analysis pending
9.8
group max
1%
  • netgear ex8000 firmware
CVE-2025-12946
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN sid

A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.

NVD description · AI analysis pending
4.4<1%
  • netgear rs700 firmware
  • netgear rax54sv2 firmware
  • netgear rax45v2 firmware
  • +1 more
CVE-2025-12945
An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network acces

An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modifications to the router software and functionality impacting its integrity. There is no additional impact to confidentiality or availability. This issue affects R7000P: through 1.3.3.154.

NVD description · AI analysis pending
1.11%
  • netgear r7000p firmware
CVE-2025-12941
Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows authenticated local WiFi users reboot the r

Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows authenticated local WiFi users reboot the router.

NVD description · AI analysis pending
5.0<1%
  • netgear c6230 firmware
  • netgear c6220 firmware
CVE-2025-12944
Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network access to the device to potentially exec

Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network access to the device to potentially execute code on the device. Please check the firmware version and update to the latest. Fixed in: DGN2200v4 firmware 1.0.0.132 or later

NVD description · AI analysis pending
6.8<1%
  • netgear dgn2200 firmware
CVE-2025-12943
Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band

Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device. Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update to the latest. Fixed in: RAX30 firmware 1.0.14.108 or later. RAXE300 firmware 1.0.9.82 or later

NVD description · AI analysis pending
5.2<1%
  • netgear rax30 firmware
  • netgear raxe300 firmware
CVE-2025-12942
Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform MiTM attack

Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform MiTM attacks and control over DNS Server to perform command execution.This issue affects R6260: through 1.1.0.86; R6850: through 1.1.0.86.

NVD description · AI analysis pending
4.8<1%
  • netgear r6260 firmware
  • netgear r6850 firmware
CVE-2025-12940
Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Mana

Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials. This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4. Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.

NVD description · AI analysis pending
0.5<1%
  • netgear wax610y firmware
  • netgear wax610 firmware
CVE-2025-44658
+1 in the same advisory: …44652
In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions.

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.

NVD description · AI analysis pending
9.8
group max
1%
  • netgear rax30 firmware
CVE-2025-44650
In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file.

In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.

NVD description · AI analysis pending
7.5<1%
  • netgear r7000 firmware
  • netgear eax80 firmware
CVE-2025-52082
+1 in the same advisory: …52081
In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint.

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the read_access parameter.

NVD description · AI analysis pending
6.5<1% PoC
  • netgear xr300 firmware