CVE-2026-9214 PUBLISHED

Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device.

Assigner: NETGEAR
Reserved: 21.05.2026 Published: 11.08.2026 Updated: 12.08.2026

Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber
CVSS Score: 4.3

Product Status

Vendor NETGEAR
Product R7000
Versions Default: unaffected
  • Version V1.0.12.216 is affected

Solutions

R7000 has reached its End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

Credits

  • quanghoa1 reporter

References

Problem Types

  • CWE-20 Improper input validation CWE

Impacts

  • CAPEC-248 Command Injection