Description
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
Published: 2026-08-11
Score: 1.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow flaw exists in several NETGEAR Nighthawk routers and satellite units, allowing an authenticated administrator to trigger a temporary device outage. The weakness, categorized as CWE‑121, can cause the affected device to become unavailable to its network, disrupting internet access and local services solely at the host level.

Affected Systems

The vulnerability affects NETGEAR MR70, MR90, MS70, MS90, and multiple RAX series routers (RAX41, RAX41v2, RAX42, RAX42v2, RAX43, RAX43v2, RAX49S, RAX50, RAX50v2, RAX54S, RAX54Sv2). End‑of‑Support models are also listed but receive no security updates and should be retired.

Risk and Exploitability

The CVSS score of 1.1 indicates a very low intrinsic severity, and the EPSS score is not available, suggesting limited real‑world exploitation potential. The flaw requires local administrative access; an attacker would need to authenticate as a device administrator or compromise an existing admin account to trigger the outage. The vulnerability is not referenced in the CISA KEV catalog, and there is no known widespread exploit. Retrospectively, the risk remains primarily a localized denial of service event, not a conduit for broader network compromise.

Generated by OpenCVE AI on August 11, 2026 at 23:23 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionMR70 (EoS) Nighthawk Mesh WiFi 6 Router V1.0.4.48 https://www.netgear.com/support/product/mr70/ MR90 Nighthawk Tri-band Mesh WiFi 6E Router V1.0.2.46 https://www.netgear.com/support/product/mr90/ MS70 Nighthawk Mesh WiFi 6 Add-on Satellite V1.0.4.48 https://www.netgear.com/support/product/ms70/ MS90 Nighthawk Tri-band Mesh WiFi 6E Add-on Satellite V1.0.2.46 https://www.netgear.com/support/product/ms90/ RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax41/ RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax41v2/ RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax42/ RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax42v2/ RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax43/ RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax43v2/ RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax49s/ RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36 https://www.netgear.com/support/product/rax50/ RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36 https://www.netgear.com/support/product/rax50v2/ RAX54S Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax54s/ RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax54sv2/ Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


OpenCVE Recommended Actions

  • Update firmware on all affected devices to the latest fixed firmware versions (e.g., MR70 V1.0.4.48, MR90 V1.0.2.46, MS70 V1.0.4.48, MS90 V1.0.2.46, or the corresponding RAX series releases) or enable automatic updates to receive the patch.
  • For devices that have reached end‑of‑support, retire them from operation and replace them with newer models that receive ongoing security updates.
  • Limit local administrative access to trusted personnel and, where possible, disable unused services that could expose vulnerable code paths.

Generated by OpenCVE AI on August 11, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 07:45:00 +0000


Tue, 11 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear mr70
Netgear mr90
Netgear ms70
Netgear ms90
Netgear rax41
Netgear rax41v2
Netgear rax42
Netgear rax42v2
Netgear rax43
Netgear rax43v2
Netgear rax49s
Netgear rax50
Netgear rax50v2
Netgear rax54s
Netgear rax54sv2
Vendors & Products Netgear
Netgear mr70
Netgear mr90
Netgear ms70
Netgear ms90
Netgear rax41
Netgear rax41v2
Netgear rax42
Netgear rax42v2
Netgear rax43
Netgear rax43v2
Netgear rax49s
Netgear rax50
Netgear rax50v2
Netgear rax54s
Netgear rax54sv2

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
Title Device administrator can interrupt the normal operation of some NETGEAR Nighthawk devices.
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 1.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/AU:Y/R:U/V:D/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-08-12T07:28:55.020Z

Reserved: 2026-06-09T02:46:43.410Z

Link: CVE-2026-11734

cve-icon Vulnrichment

Updated: 2026-08-11T19:42:40.221Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:27.140

Modified: 2026-08-28T21:16:15.740

Link: CVE-2026-11734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T23:30:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow