Vulnerability Description
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Be9300 Firmware | < 1.0.1.84 |
| Netgear | Be9300 | - |
| Netgear | Mr60 Firmware | < 1.1.8.142 |
| Netgear | Mr60 | - |
| Netgear | Ms60 Firmware | < 1.1.8.142 |
| Netgear | Ms60 | - |
| Netgear | R6700Ax Firmware | < 1.0.18.164 |
| Netgear | R6700Ax | - |
| Netgear | Rax10 Firmware | < 1.0.5.50 |
| Netgear | Rax10 | - |
| Netgear | Rax120 Firmware | < 1.2.10.56 |
| Netgear | Rax120 | - |
| Netgear | Rax120V2 Firmware | < 1.2.10.56 |
| Netgear | Rax120V2 | - |
| Netgear | Rax20 Firmware | < 1.0.17.142 |
| Netgear | Rax20 | - |
| Netgear | Rax28 Firmware | < 1.0.14.108 |
| Netgear | Rax28 | - |
| Netgear | Rax29 Firmware | < 1.0.14.108 |
| Netgear | Rax29 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-AdvisoryVendor Advisory
- https://www.netgear.com/support/product/r7000/Product
- https://www.netgear.com/support/product/raxe500/Product
- https://www.netgear.com/support/product/rs700/Product
FAQ
What is CVE-2026-11738?
CVE-2026-11738 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and fun...
How severe is CVE-2026-11738?
CVE-2026-11738 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11738?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Be9300 Firmware, Netgear Be9300, Netgear Mr60 Firmware, Netgear Mr60, Netgear Ms60 Firmware.