Description
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
Published: 2026-08-11
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow that can be triggered by an authenticated administrator. Exploitation allows the attacker to modify the router’s firmware or operational behavior, effectively giving them high‑level control over the device. The weakness is identified by CWE‑121, a classic buffer overflow flaw that can be used for remote code execution when the overflow is successfully triggered.

Affected Systems

Affected devices include NETGEAR Nighthawk R7000, RAX20, RAX35v2, RAX41, RAX41v2, RAX42, RAX42v2, RAX43, RAX43v2, RAX45, RAX49S, RAX50, RAX50S, RAX50v2, RAX54Sv2, RAX54v2, RAXE450, RAXE500, XR1000, and XR1000v2. Firmware versions before the fixed releases are vulnerable. The patched firmware versions that fix the issue are: V1.0.16.132 or V1.1.4.28 on RAX35v2, RAX41v2, RAX42v2, RAX43, RAX43v2, RAX49S, RAX50v2, RAX54Sv2, RAX54v2, and V1.2.14.114 on RAXE500, as well as V1.1.0.22 on XR1000 and XR1000v2. Devices marked End‑of‑Support (EoS) such as R7000, RAX20, RAX45, RAX50S, RAXE450, and others no longer receive security updates and should be retired.

Risk and Exploitability

The CVSS score of 1.9 indicates low severity when assessed in isolation, and the EPSS score is not available. The vulnerability requires authenticated admin access, often via the web interface, so the likely attack vector involves an attacker who has already gained local or remote administrative credentials. Because the issue is a buffer overflow, the risk of exploitation is high if the attacker can reach the vulnerable code; however, the overall likelihood is uncertain given the absence of EPSS data and the lack of listing in KEV. Network administrators should treat this as a potential privilege‑escalation vector that can lead to remote code execution on affected routers.

Generated by OpenCVE AI on August 11, 2026 at 22:55 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionR7000 (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit RouterEOSRAX20 (EoS) 4-Stream AX1800 WiFi 6 RouterEOSRAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router V1.0.16.132 https://www.netgear.com/support/product/rax35v2/ RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi RouterEOSRAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax41v2/ RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi RouterEOSRAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax42v2/ RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.0.16.132 https://www.netgear.com/support/product/rax43/ RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax43v2/ RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi RouterEOSRAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax49s/ RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.16.132 https://www.netgear.com/support/product/rax50/ RAX50S (EoS) Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.16.132 https://www.netgear.com/support/product/rax50s/ RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.4.28 https://www.netgear.com/support/product/rax50v2/ RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax54sv2/ RAX54v2 Nighthawk AX6 6-Stream AX5400 WiFi RouterV1.1.4.28RAXE450 (EoS) Nighthawk AXE10000 Tri-Band WiFi 6E RouterEOSRAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.114 https://www.netgear.com/support/product/raxe500/ XR1000 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000/ XR1000v2 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000v2/ Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


OpenCVE Recommended Actions

  • Update the router’s firmware to the latest fixed version for your specific model (for example, upgrade RAX42v2 to firmware V1.1.4.28).
  • If the device is End‑of‑Support and no patched firmware is available, replace it with a newer NETGEAR model and apply the current firmware that includes the fix.
  • Ensure automatic firmware updates are enabled; if not, manually verify that the device is running a patched firmware version.

Generated by OpenCVE AI on August 11, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 07:45:00 +0000


Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
Title Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models
First Time appeared Netgear
Netgear r7000
Netgear rax20
Netgear rax35v2
Netgear rax41
Netgear rax41v2
Netgear rax42
Netgear rax42v2
Netgear rax43
Netgear rax43v2
Netgear rax45
Netgear rax49s
Netgear rax50
Netgear rax50s
Netgear rax50v2
Netgear rax54sv2
Netgear rax54v2
Netgear raxe450
Netgear raxe500
Netgear xr1000
Netgear xr1000v2
Weaknesses CWE-121
CPEs cpe:2.3:a:netgear:r7000:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax20:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax35v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax41:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax41v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax42:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax42v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax43:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax43v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax45:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax49s:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax50:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax50s:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax50v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax54sv2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax54v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:raxe450:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:raxe500:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:xr1000:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:xr1000v2:*:*:*:*:*:*:*:*
Vendors & Products Netgear
Netgear r7000
Netgear rax20
Netgear rax35v2
Netgear rax41
Netgear rax41v2
Netgear rax42
Netgear rax42v2
Netgear rax43
Netgear rax43v2
Netgear rax45
Netgear rax49s
Netgear rax50
Netgear rax50s
Netgear rax50v2
Netgear rax54sv2
Netgear rax54v2
Netgear raxe450
Netgear raxe500
Netgear xr1000
Netgear xr1000v2
References
Metrics cvssV4_0

{'score': 1.9, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:Y/R:U/V:D/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-08-12T07:32:29.550Z

Reserved: 2026-06-09T02:46:44.333Z

Link: CVE-2026-11735

cve-icon Vulnrichment

Updated: 2026-08-11T17:10:57.043Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:27.360

Modified: 2026-08-28T21:16:15.740

Link: CVE-2026-11735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T23:45:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow