Vulnerability Description
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Ms90 Firmware | < 1.0.2.46 |
| Netgear | Ms90 | - |
| Netgear | Rax20 Firmware | < 1.0.17.142 |
| Netgear | Rax20 | - |
| Netgear | Rax200 Firmware | < 1.0.11.148 |
| Netgear | Rax200 | - |
| Netgear | Rax35 Firmware | < 1.0.17.142 |
| Netgear | Rax35 | - |
| Netgear | Rax35V2 Firmware | < 1.0.17.142 |
| Netgear | Rax35V2 | - |
| Netgear | Rax41 Firmware | < 1.1.6.36 |
| Netgear | Rax41 | - |
| Netgear | Rax41V2 Firmware | < 1.1.6.36 |
| Netgear | Rax41V2 | - |
| Netgear | Rax42 Firmware | < 1.1.6.36 |
| Netgear | Rax42 | - |
| Netgear | Rax42V2 Firmware | < 1.1.6.36 |
| Netgear | Rax42V2 | - |
| Netgear | Rax43 Firmware | < 1.1.6.36 |
| Netgear | Rax43 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-AdvisoryVendor Advisory
- https://www.netgear.com/support/product/mr60/Product
- https://www.netgear.com/support/product/mr70/Product
- https://www.netgear.com/support/product/mr90/Product
- https://www.netgear.com/support/product/ms60/Product
- https://www.netgear.com/support/product/ms70/Product
- https://www.netgear.com/support/product/ms90/Product
- https://www.netgear.com/support/product/rax20/Product
- https://www.netgear.com/support/product/rax200/Product
- https://www.netgear.com/support/product/rax35/Product
- https://www.netgear.com/support/product/rax35v2/Product
- https://www.netgear.com/support/product/rax41/Product
- https://www.netgear.com/support/product/rax41v2/Product
- https://www.netgear.com/support/product/rax42/Product
- https://www.netgear.com/support/product/rax42v2/Product
FAQ
What is CVE-2026-11739?
CVE-2026-11739 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the mid...
How severe is CVE-2026-11739?
CVE-2026-11739 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11739?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Ms90 Firmware, Netgear Ms90, Netgear Rax20 Firmware, Netgear Rax20, Netgear Rax200 Firmware.