Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.9epss 0.9%
exploitation probability
0.9%top 41% of all CVEs
observed exploitation
nono source reports it
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber
Affected products
NETGEAR · BE9300NETGEAR · MR60NETGEAR · MS60NETGEAR · R6700AXNETGEAR · RAX10NETGEAR · RAX120NETGEAR · RAX120v2NETGEAR · RAX20NETGEAR · RAX28NETGEAR · RAX29NETGEAR · RAX30NETGEAR · RAX36SNETGEAR · RAX43NETGEAR · RAX45NETGEAR · RAX50NETGEAR · RAX70NETGEAR · RBR760NETGEAR · RBS760NETGEAR · RS100NETGEAR · RS200NETGEAR · RS280NETGEAR · RS300NETGEAR · RS500NETGEAR · RS600NETGEAR · RS70NETGEAR · RS90References
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/be9300/https://www.netgear.com/support/product/mr60/https://www.netgear.com/support/product/ms60/https://www.netgear.com/support/product/r6700ax/https://www.netgear.com/support/product/rax10/https://www.netgear.com/support/product/rax120/https://www.netgear.com/support/product/rax120v2/https://www.netgear.com/support/product/rax20/https://www.netgear.com/support/product/rax28/https://www.netgear.com/support/product/rax29/https://www.netgear.com/support/product/rax30/