CVE-2026-9216
Insufficient input validation vulnerability exists in certain NETGEAR RAX Models
CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
| CWE | CWE-121 |
| Vendor | netgear |
| Product | rax30 |
| Published | Sep 8, 2026 |
| Last Updated | Sep 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for netgear rax30
Be the first to know when new low vulnerabilities affecting netgear rax30 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected Versions
NETGEAR / RAX30
0 < V1.0.9.92
NETGEAR / RAX35
0 < V1.0.10.72
NETGEAR / RAX38
0 < V1.0.6.106
NETGEAR / RAX40
0 < V1.0.6.106
NETGEAR / RAXE300
0 < V1.0.10.72
References
netgear.com: https://www.netgear.com/support/product/rax30 netgear.com: https://www.netgear.com/support/product/rax35 netgear.com: https://www.netgear.com/support/product/rax38 netgear.com: https://www.netgear.com/support/product/rax40 netgear.com: https://www.netgear.com/support/product/raxe300 kb.netgear.com: https://kb.netgear.com/000070912/September-2026-NETGEAR-Security-Advisory
Credits
mr_mee