CVE-2026-11737 PUBLISHED

Some NETGEAR Nighthawk devices allow administrators to tamper with the device

Assigner: NETGEAR
Reserved: 09.06.2026 Published: 11.08.2026 Updated: 12.08.2026

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber
CVSS Score: 4.3

Product Status

Vendor NETGEAR
Product RAX20
Versions Default: unaffected
  • affected from 0 to V1.0.18.144 (excl.)
Vendor NETGEAR
Product RAX41
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX41v2
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX42
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX42v2
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX43
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX43v2
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX45
Versions Default: unaffected
  • affected from 0 to V1.0.17.142 (excl.)
Vendor NETGEAR
Product RAX49S
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX50
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX50v2
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX54S
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)
Vendor NETGEAR
Product RAX54Sv2
Versions Default: unaffected
  • affected from 0 to V1.1.6.36 (excl.)

Solutions

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

ProductFixed VersionRAX20 (EoS) 4-Stream AX1800 WiFi 6 Router V1.0.18.144 https://www.netgear.com/support/product/rax20/ RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax41/ RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax41v2/ RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax42/ RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax42v2/ RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax43/ RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax43v2/ RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router V1.0.17.142 https://www.netgear.com/support/product/rax45/ RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax49s/ RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36 https://www.netgear.com/support/product/rax50/ RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36 https://www.netgear.com/support/product/rax50v2/ RAX54S Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax54s/ RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax54sv2/

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

Credits

  • Matt19 finder

References

Problem Types

  • CWE-20 Improper input validation CWE

Impacts

  • CAPEC-248 Command Injection