Vulnerability Description
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Be9300 Firmware | < 1.0.1.84 |
| Netgear | Be9300 | - |
| Netgear | Mr60 Firmware | < 1.1.8.142 |
| Netgear | Mr60 | - |
| Netgear | Ms60 Firmware | < 1.1.8.142 |
| Netgear | Ms60 | - |
| Netgear | R6700Ax Firmware | < 1.0.18.164 |
| Netgear | R6700Ax | - |
| Netgear | Rax10 Firmware | < 1.0.5.50 |
| Netgear | Rax10 | - |
| Netgear | Rax120 Firmware | < 1.2.10.56 |
| Netgear | Rax120 | - |
| Netgear | Rax120V2 Firmware | < 1.2.10.56 |
| Netgear | Rax120V2 | - |
| Netgear | Rax20 Firmware | < 1.0.17.142 |
| Netgear | Rax20 | - |
| Netgear | Rax28 Firmware | < 1.0.14.108 |
| Netgear | Rax28 | - |
| Netgear | Rax29 Firmware | < 1.0.14.108 |
| Netgear | Rax29 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-AdvisoryVendor Advisory
- https://www.netgear.com/support/product/be9300/Product
- https://www.netgear.com/support/product/mr60/Product
- https://www.netgear.com/support/product/ms60/Product
- https://www.netgear.com/support/product/r6700ax/Product
- https://www.netgear.com/support/product/rax10/Product
- https://www.netgear.com/support/product/rax120/Product
- https://www.netgear.com/support/product/rax120v2/Product
- https://www.netgear.com/support/product/rax20/Product
- https://www.netgear.com/support/product/rax28/Product
- https://www.netgear.com/support/product/rax29/Product
- https://www.netgear.com/support/product/rax30/Product
- https://www.netgear.com/support/product/rax36s/Product
- https://www.netgear.com/support/product/rax43/Product
- https://www.netgear.com/support/product/rax45/Product
FAQ
What is CVE-2026-11814?
CVE-2026-11814 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise ...
How severe is CVE-2026-11814?
CVE-2026-11814 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11814?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Be9300 Firmware, Netgear Be9300, Netgear Mr60 Firmware, Netgear Mr60, Netgear Ms60 Firmware.