CVE-2026-9211
published 2026-06-09CVE-2026-9211: An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
PriorityP428medium5.2CVSS 4.0
AVAACLATPPRNUINVCHVIHVAHSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVDRELUAmber
EPSS
0.24%
14.3th percentile
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | cax30 | < V2.2.1.4 | V2.2.1.4 |
| netgear | rax30 | < V1.0.10.94 | V1.0.10.94 |
| netgear | rax5 | < V1.0.5.34 | V1.0.5.34 |
| netgear | raxe300 | < V1.0.10.72 | V1.0.10.72 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
ghsa_unreviewed·2026-06-09
CVE-2026-9211 [MEDIUM] CWE-20 An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
VulDB
Netgear CAX30/RAX30/RAX5/RAXE300 prior 2.2.1.4 improper authorization
vuldb·2026-06-09·CVSS 5.2
CVE-2026-9211 [MEDIUM] Netgear CAX30/RAX30/RAX5/RAXE300 prior 2.2.1.4 improper authorization
A vulnerability was found in Netgear CAX30, RAX30, RAX5 and RAXE300. It has been rated as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes improper authorization.
This vulnerability is registered as CVE-2026-9211. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-09
Published