Vulnerabilities (CVE)

Filtered by vendor Netgear Subscribe
Filtered by product Rax50 Firmware
Total 56 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-11814 1 Netgear 52 Be9300, Be9300 Firmware, Mr60 and 49 more 2026-09-09 N/A 6.8 MEDIUM
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
CVE-2026-11738 1 Netgear 52 Be9300, Be9300 Firmware, Mr60 and 49 more 2026-09-09 N/A 4.4 MEDIUM
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-11739 1 Netgear 54 Mr60, Mr60 Firmware, Mr70 and 51 more 2026-09-09 N/A 6.4 MEDIUM
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
CVE-2026-11737 1 Netgear 26 Rax20, Rax20 Firmware, Rax41 and 23 more 2026-09-09 N/A 4.5 MEDIUM
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
CVE-2026-11733 1 Netgear 22 Rax41, Rax41 Firmware, Rax41v2 and 19 more 2026-09-09 N/A 4.9 MEDIUM
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
CVE-2026-11734 1 Netgear 30 Mr70, Mr70 Firmware, Mr90 and 27 more 2026-09-09 N/A 2.7 LOW
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
CVE-2026-11736 1 Netgear 38 Rax20, Rax20 Firmware, Rax35v2 and 35 more 2026-09-09 N/A 4.9 MEDIUM
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
CVE-2026-11735 1 Netgear 40 R7000, R7000 Firmware, Rax20 and 37 more 2026-09-09 N/A 4.9 MEDIUM
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
CVE-2026-9210 1 Netgear 62 Ex3700, Ex3700 Firmware, Ex3800 and 59 more 2026-07-23 N/A 4.5 MEDIUM
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
CVE-2026-0410 1 Netgear 38 R7000, R7000 Firmware, Rax20 and 35 more 2026-07-23 N/A 4.5 MEDIUM
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
CVE-2026-0418 1 Netgear 70 Cbr750, Cbr750 Firmware, Ex6120 and 67 more 2026-07-23 N/A 4.5 MEDIUM
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
CVE-2026-0417 1 Netgear 54 Mr60, Mr60 Firmware, Mr70 and 51 more 2026-07-23 N/A 4.5 MEDIUM
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
CVE-2025-12946 1 Netgear 36 Mr90, Mr90 Firmware, Ms90 and 33 more 2026-06-17 N/A 7.5 HIGH
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.
CVE-2024-57235 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.
CVE-2024-57234 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
CVE-2024-57233 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.
CVE-2024-57232 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
CVE-2024-57231 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
CVE-2024-57230 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.
CVE-2024-57229 1 Netgear 2 Rax50, Rax50 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.