CVE-2026-11739
published 2026-08-11CVE-2026-11739: A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify…
PriorityP433medium4.9CVSS 4.0
AVAACHATPPRNUINVCHVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUNRUVDRELUAmber
EPSS
1.05%
61.6th percentile
A command injection vulnerability in certain affected NETGEAR Nighthawk
devices allows a network-adjacent attacker with the ability to intercept
and modify local network traffic (attacker in the middle) to compromise
the confidentiality and integrity of the affected device.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | mr60 | < V1.1.8.142 | V1.1.8.142 |
| netgear | mr70 | < V1.0.4.48 | V1.0.4.48 |
| netgear | mr90 | < V1.0.2.46 | V1.0.2.46 |
| netgear | ms60 | < V1.1.8.142 | V1.1.8.142 |
| netgear | ms70 | < V1.0.4.48 | V1.0.4.48 |
| netgear | ms90 | < V1.0.2.46 | V1.0.2.46 |
| netgear | rax20 | < V1.0.17.142 | V1.0.17.142 |
| netgear | rax200 | < V1.0.11.148 | V1.0.11.148 |
| netgear | rax35 | < V1.0.17.142 | V1.0.17.142 |
| netgear | rax35v2 | < V1.0.17.142 | V1.0.17.142 |
| netgear | rax41 | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax41v2 | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax42 | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax42v2 | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax43 | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax43v2 | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax45 | < V1.0.17.142 | V1.0.17.142 |
| netgear | rax49s | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax50 | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax50v2 | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax54s | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax54sv2 | < V1.1.6.36 | V1.1.6.36 |
| netgear | rax80 | < V1.0.11.148 | V1.0.11.148 |
| netgear | raxe500 | < V1.2.14.110 | V1.2.14.110 |
| netgear | rs700 | < V1.0.9.6 | V1.0.9.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/mr60/https://www.netgear.com/support/product/mr70/https://www.netgear.com/support/product/mr90/https://www.netgear.com/support/product/ms60/https://www.netgear.com/support/product/ms70/https://www.netgear.com/support/product/ms90/https://www.netgear.com/support/product/rax20/https://www.netgear.com/support/product/rax200/https://www.netgear.com/support/product/rax35/https://www.netgear.com/support/product/rax35v2/https://www.netgear.com/support/product/rax41/https://www.netgear.com/support/product/rax41v2/https://www.netgear.com/support/product/rax42/https://www.netgear.com/support/product/rax42v2/https://www.netgear.com/support/product/rax43/https://www.netgear.com/support/product/rax43v2/https://www.netgear.com/support/product/rax45/https://www.netgear.com/support/product/rax49s/https://www.netgear.com/support/product/rax50/https://www.netgear.com/support/product/rax50v2/https://www.netgear.com/support/product/rax80/https://www.netgear.com/support/product/raxe500/https://www.netgear.com/support/product/rs700/https://www.netgear.com/support/product/xr1000/https://www.netgear.com/support/product/xr1000v2/
2026-08-11
Published