cbcvebase.

Netgear Rax43 vulnerabilities

13 known vulnerabilities affecting netgear/rax43.

Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM11LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-12946P3HIGHCVSS 7.5fixed in V1.0.17.1422025-12-09
CVE-2025-12946 [HIGH] CWE-20 CVE-2025-12946: A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper i A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6
nvd
CVE-2026-11739P3MEDIUMCVSS 6.4fixed in V1.1.6.362026-08-11
CVE-2026-11739 [MEDIUM] CWE-78 CVE-2026-11739: A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-ad A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
nvd
CVE-2026-11814P3MEDIUMCVSS 6.8fixed in V1.0.17.1422026-08-11
CVE-2026-11814 [MEDIUM] CWE-295 CVE-2026-11814: A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker wi A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
nvd
CVE-2026-11733P4MEDIUMCVSS 4.9fixed in V1.1.6.362026-08-11
CVE-2026-11733 [MEDIUM] CWE-121 CVE-2026-11733: A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to tempor A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
nvd
CVE-2026-11735P4MEDIUMCVSS 4.9fixed in V1.0.16.1322026-08-11
CVE-2026-11735 [MEDIUM] CWE-121 CVE-2026-11735: A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authentica A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
nvd
CVE-2026-11736P4MEDIUMCVSS 4.9fixed in V1.0.16.1322026-08-11
CVE-2026-11736 [MEDIUM] CWE-20 CVE-2026-11736: A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
nvd
CVE-2026-62658P4MEDIUMCVSS 4.7fixed in V1.0.17.1422026-07-14
CVE-2026-62658 [MEDIUM] CWE-20 CVE-2026-62658: A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow some A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.
nvd
CVE-2026-0418P4MEDIUMCVSS 4.5fixed in V1.0.11.1122026-06-09
CVE-2026-0418 [MEDIUM] CWE-15 CVE-2026-0418: Insufficient configuration management in the listed devices allows authenticated administrators conn Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
nvd
CVE-2026-0417P4MEDIUMCVSS 4.5fixed in V1.0.12.1202026-06-09
CVE-2026-0417 [MEDIUM] CWE-20 CVE-2026-0417: Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated admin Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
nvd
CVE-2026-9210P4MEDIUMCVSS 4.5fixed in V1.0.12.1202026-06-09
CVE-2026-9210 [MEDIUM] CWE-20 CVE-2026-9210: Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
nvd
CVE-2026-11737P4MEDIUMCVSS 4.5fixed in V1.1.6.362026-08-11
CVE-2026-11737 [MEDIUM] CWE-20 CVE-2026-11737: Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admin Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
nvd
CVE-2026-0410P4MEDIUMCVSS 4.5fixed in V1.0.16.1322026-06-09
CVE-2026-0410 [MEDIUM] CWE-20 CVE-2026-0410: Authenticated administrators connected to the local network can gain elevated access to the router Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
nvd
CVE-2026-11734P4LOWCVSS 2.7fixed in V1.1.6.362026-08-11
CVE-2026-11734 [LOW] CWE-121 CVE-2026-11734: A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to c A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
nvd
Netgear Rax43 vulnerabilities | cvebase