CVE-2026-11814
published 2026-08-11CVE-2026-11814: A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network…
PriorityP343medium6.8CVSS 3.1
AVAACHPRNUINSUCHIHAN
EPSS
0.91%
58.0th percentile
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | be9300 | < V1.0.1.84 | V1.0.1.84 |
| netgear | be9300_firmware | < 1.0.1.84 | 1.0.1.84 |
| netgear | mr60 | < V1.1.8.142 | V1.1.8.142 |
| netgear | mr60_firmware | < 1.1.8.142 | 1.1.8.142 |
| netgear | ms60 | < V1.1.8.142 | V1.1.8.142 |
| netgear | ms60_firmware | < 1.1.8.142 | 1.1.8.142 |
| netgear | r6700ax | < V1.0.18.164 | V1.0.18.164 |
| netgear | r6700ax_firmware | < 1.0.18.164 | 1.0.18.164 |
| netgear | rax10 | < V1.0.5.50 | V1.0.5.50 |
| netgear | rax10_firmware | < 1.0.5.50 | 1.0.5.50 |
| netgear | rax120 | < V1.2.10.56 | V1.2.10.56 |
| netgear | rax120_firmware | < 1.2.10.56 | 1.2.10.56 |
| netgear | rax120v2 | < V1.2.10.56 | V1.2.10.56 |
| netgear | rax120v2_firmware | < 1.2.10.56 | 1.2.10.56 |
| netgear | rax20 | < V1.0.17.142 | V1.0.17.142 |
| netgear | rax20_firmware | < 1.0.17.142 | 1.0.17.142 |
| netgear | rax28 | < V1.0.14.108 | V1.0.14.108 |
| netgear | rax28_firmware | < 1.0.14.108 | 1.0.14.108 |
| netgear | rax29 | < V1.0.14.108 | V1.0.14.108 |
| netgear | rax29_firmware | < 1.0.14.108 | 1.0.14.108 |
| netgear | rax30 | < V1.0.14.108 | V1.0.14.108 |
| netgear | rax30_firmware | < 1.0.14.108 | 1.0.14.108 |
| netgear | rax36s | < V1.0.5.50 | V1.0.5.50 |
| netgear | rax36s_firmware | < 1.0.5.50 | 1.0.5.50 |
| netgear | rax43 | < V1.0.17.142 | V1.0.17.142 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.04.9MEDIUMCVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/be9300/https://www.netgear.com/support/product/mr60/https://www.netgear.com/support/product/ms60/https://www.netgear.com/support/product/r6700ax/https://www.netgear.com/support/product/rax10/https://www.netgear.com/support/product/rax120/https://www.netgear.com/support/product/rax120v2/https://www.netgear.com/support/product/rax20/https://www.netgear.com/support/product/rax28/https://www.netgear.com/support/product/rax29/https://www.netgear.com/support/product/rax30/https://www.netgear.com/support/product/rax36s/https://www.netgear.com/support/product/rax43/https://www.netgear.com/support/product/rax45/https://www.netgear.com/support/product/rax50/https://www.netgear.com/support/product/rax70/https://www.netgear.com/support/product/rbr760/https://www.netgear.com/support/product/rbs760/https://www.netgear.com/support/product/rs100/https://www.netgear.com/support/product/rs200/https://www.netgear.com/support/product/rs280/https://www.netgear.com/support/product/rs300/https://www.netgear.com/support/product/rs500/https://www.netgear.com/support/product/rs600/https://www.netgear.com/support/product/rs70/https://www.netgear.com/support/product/rs90/
2026-08-11
Published