MEDIUM · 6.4

CVE-2026-11739

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the mid...

Vulnerability Description

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.

CVSS Score

6.4

MEDIUM

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
NetgearMs90 Firmware< 1.0.2.46
NetgearMs90-
NetgearRax20 Firmware< 1.0.17.142
NetgearRax20-
NetgearRax200 Firmware< 1.0.11.148
NetgearRax200-
NetgearRax35 Firmware< 1.0.17.142
NetgearRax35-
NetgearRax35V2 Firmware< 1.0.17.142
NetgearRax35V2-
NetgearRax41 Firmware< 1.1.6.36
NetgearRax41-
NetgearRax41V2 Firmware< 1.1.6.36
NetgearRax41V2-
NetgearRax42 Firmware< 1.1.6.36
NetgearRax42-
NetgearRax42V2 Firmware< 1.1.6.36
NetgearRax42V2-
NetgearRax43 Firmware< 1.1.6.36
NetgearRax43-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-11739?

CVE-2026-11739 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the mid...

How severe is CVE-2026-11739?

CVE-2026-11739 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-11739?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear Ms90 Firmware, Netgear Ms90, Netgear Rax20 Firmware, Netgear Rax20, Netgear Rax200 Firmware.