CVE-2026-9216
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Weakness
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Affected products
- netgear rax30_firmware
- netgear rax30
- netgear rax35_firmware
- netgear rax35
- netgear rax38_firmware
- netgear rax38
- netgear rax40_firmware
- netgear rax40
References
- https://kb.netgear.com/000070912/September-2026-NETGEAR-Security-Advisory
- https://www.netgear.com/support/product/rax30
- https://www.netgear.com/support/product/rax35
- https://www.netgear.com/support/product/rax38
- https://www.netgear.com/support/product/rax40
- https://www.netgear.com/support/product/raxe300
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.