CVE-2026-9213
published 2026-06-09CVE-2026-9213: A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the…
PriorityP341medium6.9CVSS 4.0
AVNACHATPPRNUINVCHVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.40%
32.0th percentile
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | mr70 | < V1.0.4.48 | V1.0.4.48 |
| netgear | ms70 | < V1.0.4.48 | V1.0.4.48 |
| netgear | raxe500 | < V1.2.14.114 | V1.2.14.114 |
| netgear | xr1000 | < V1.0.2.86 | V1.0.2.86 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper traffic between the router and the Internet, to execute code on the device.
ghsa_unreviewed·2026-06-09
CVE-2026-9213 [MEDIUM] CWE-20 A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper traffic between the router and the Internet, to execute code on the device.
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper traffic between the router and the Internet, to execute code on the device.
VulDB
Netgear MR70/MS70/RAXE500/XR1000 prior 1.0.4.48 input validation
vuldb·2026-06-09·CVSS 6.9
CVE-2026-9213 [MEDIUM] Netgear MR70/MS70/RAXE500/XR1000 prior 1.0.4.48 input validation
A vulnerability labeled as problematic has been found in Netgear MR70, MS70, RAXE500 and XR1000. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper input validation.
This vulnerability is traded as CVE-2026-9213. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-09
Published