Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Advisories

No advisories yet.

Fixes

Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionR7000 (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit RouterEOSRAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.114 https://www.netgear.com/support/product/raxe500/ RS700 Nighthawk BE19000 WiFi 7 Tri-Band Router V1.0.7.66 https://www.netgear.com/support/product/rs700/ Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


Workaround

No workaround given by the vendor.

History

Wed, 12 Aug 2026 07:45:00 +0000


Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Title Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.
First Time appeared Netgear
Netgear r7000
Netgear raxe500
Netgear rs700
Weaknesses CWE-20
CPEs cpe:2.3:a:netgear:r7000:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:raxe500:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rs700:*:*:*:*:*:*:*:*
Vendors & Products Netgear
Netgear r7000
Netgear raxe500
Netgear rs700
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-08-12T07:41:53.324Z

Reserved: 2026-06-09T02:46:47.287Z

Link: CVE-2026-11738

cve-icon Vulnrichment

Updated: 2026-08-11T19:42:24.631Z

cve-icon NVD

Status : Received

Published: 2026-08-11T16:17:28.120

Modified: 2026-08-12T08:17:16.067

Link: CVE-2026-11738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T23:15:12Z

Weaknesses