CVE-2026-9216

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:rax30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax30:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:rax35_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax35:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:rax38_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax38:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:rax40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax40:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:raxe300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:raxe300:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-08 18:21

Updated : 2026-09-11 21:20


NVD link : CVE-2026-9216

Mitre link : CVE-2026-9216

CVE.ORG link : CVE-2026-9216


JSON object : View

Products Affected

netgear

  • rax40
  • rax38
  • raxe300_firmware
  • rax35_firmware
  • rax40_firmware
  • raxe300
  • rax30_firmware
  • rax38_firmware
  • rax35
  • rax30
CWE
CWE-121

Stack-based Buffer Overflow