NETGEAR models allows authenticated administrators connected to the
local network to make unauthorized modification to the device software and
functionality.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionRAX20 (EoS) 4-Stream AX1800 WiFi 6 Router V1.0.18.144 https://www.netgear.com/support/product/rax20/ RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax41/ RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax41v2/ RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax42/ RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax42v2/ RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax43/ RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax43v2/ RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router V1.0.17.142 https://www.netgear.com/support/product/rax45/ RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax49s/ RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36 https://www.netgear.com/support/product/rax50/ RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36 https://www.netgear.com/support/product/rax50v2/ RAX54S Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax54s/ RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax54sv2/ Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
Workaround
No workaround given by the vendor.
Wed, 12 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 11 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear
Netgear rax20 Netgear rax41 Netgear rax41v2 Netgear rax42 Netgear rax42v2 Netgear rax43 Netgear rax43v2 Netgear rax45 Netgear rax49s Netgear rax50 Netgear rax50v2 Netgear rax54s Netgear rax54sv2 |
|
| Vendors & Products |
Netgear
Netgear rax20 Netgear rax41 Netgear rax41v2 Netgear rax42 Netgear rax42v2 Netgear rax43 Netgear rax43v2 Netgear rax45 Netgear rax49s Netgear rax50 Netgear rax50v2 Netgear rax54s Netgear rax54sv2 |
Tue, 11 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality. | |
| Title | Some NETGEAR Nighthawk devices allow administrators to tamper with the device | |
| Weaknesses | CWE-20 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NETGEAR
Published:
Updated: 2026-08-12T07:39:19.719Z
Reserved: 2026-06-09T02:46:46.338Z
Link: CVE-2026-11737
Updated: 2026-08-11T19:43:08.170Z
Status : Received
Published: 2026-08-11T16:17:27.917
Modified: 2026-08-12T08:17:15.570
Link: CVE-2026-11737
No data.
OpenCVE Enrichment
Updated: 2026-08-11T23:15:12Z