CVE-2026-11738 PUBLISHED

Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.

Assigner: NETGEAR
Reserved: 09.06.2026 Published: 11.08.2026 Updated: 12.08.2026

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber
CVSS Score: 4.3

Product Status

Vendor NETGEAR
Product R7000
Versions Default: affected
  • affected from 0 to * (excl.)
Vendor NETGEAR
Product RAXE500
Versions Default: unaffected
  • affected from 0 to V1.2.14.114 (excl.)
Vendor NETGEAR
Product RS700
Versions Default: unaffected
  • affected from 0 to V1.0.7.66 (excl.)

Solutions

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

ProductFixed VersionR7000 (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit RouterEOSRAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.114 https://www.netgear.com/support/product/raxe500/ RS700 Nighthawk BE19000 WiFi 7 Tri-Band Router V1.0.7.66 https://www.netgear.com/support/product/rs700/

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

Credits

  • fxc233 finder

References

Problem Types

  • CWE-20 Improper input validation CWE