CVE-2026-9216 PUBLISHED

Insufficient input validation vulnerability exists in certain NETGEAR RAX Models

Assigner: NETGEAR
Reserved: 21.05.2026 Published: 08.09.2026 Updated: 09.09.2026

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/AU:Y/R:A/V:D/RE:L/U:Amber
CVSS Score: 1.2

Product Status

Vendor NETGEAR
Product RAX30
Versions Default: unaffected
  • affected from 0 to V1.0.9.92 (excl.)
Vendor NETGEAR
Product RAX35
Versions Default: unaffected
  • affected from 0 to V1.0.10.72 (excl.)
Vendor NETGEAR
Product RAX38
Versions Default: unaffected
  • affected from 0 to V1.0.6.106 (excl.)
Vendor NETGEAR
Product RAX40
Versions Default: unaffected
  • affected from 0 to V1.0.6.106 (excl.)
Vendor NETGEAR
Product RAXE300
Versions Default: unaffected
  • affected from 0 to V1.0.10.72 (excl.)

Solutions

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

ProductFixed VersionRAX30 Nighthawk AX5 5-Stream AX2400 WiFi 6 Router V1.0.9.92 https://www.netgear.com/support/product/rax30 RAX35 Nighthawk AX4 4-Stream WiFi 6 Router V1.0.10.72 https://www.netgear.com/support/product/rax35 RAX38 (EoS) Nighthawk AX4 4-Stream AX3000 WiFi Router V1.0.6.106 https://www.netgear.com/support/product/rax38 RAX40 (EoS) Nighthawk AX4 4-Stream WiFi Router V1.0.6.106 https://www.netgear.com/support/product/rax40 RAXE300 Nighthawk AXE7800 Tri-Band WiFi 6E Router V1.0.10.72 https://www.netgear.com/support/product/raxe300

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

Credits

  • mr_mee finder

References

Problem Types

  • CWE-121 Stack-based buffer overflow CWE