Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2026-9216 Details
Description
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Metrics
CVSS 4.0 Severity and Vector Strings:
CNA: Netgear, Inc.CVSS-B:5.1 MEDIUMVector:CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 8, 2026Exploitation: NoneAutomatable: NoTechnical Impact: Partial
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.netgear.com/000070912/September-2026-NETGEAR-Security-Advisory | Netgear, Inc. | Vendor Advisory |
| https://www.netgear.com/support/product/rax30 | Netgear, Inc. | Product |
| https://www.netgear.com/support/product/rax35 | Netgear, Inc. | Product |
| https://www.netgear.com/support/product/rax38 | Netgear, Inc. | Product |
| https://www.netgear.com/support/product/rax40 | Netgear, Inc. | Product |
| https://www.netgear.com/support/product/raxe300 | Netgear, Inc. | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | Netgear, Inc. |
Affected Products
| Product | Versions |
|---|---|
| netgear rax30 firmware | < 1.0.9.92 |
CPE
Remediation
| |
| netgear rax30 | All versions |
CPE
Remediation
| |
| netgear rax35 firmware | < 1.0.10.72 |
CPE
Remediation
| |
| netgear rax35 | All versions |
CPE
Remediation
| |
| netgear rax38 firmware | < 1.0.6.106 |
CPE
Remediation
| |
| netgear rax38 | All versions |
CPE
Remediation
| |
| netgear rax40 firmware | < 1.0.6.106 |
CPE
Remediation
| |
| netgear rax40 | All versions |
CPE
Remediation
| |
| netgear raxe300 firmware | < 1.0.10.72 |
CPE
Remediation
| |
| netgear raxe300 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | Initial Analysis | [email protected] |
| Sep 9, 2026 | CVE Modified | Netgear, Inc. |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | Netgear, Inc. |