Description
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
Published: 2026-08-11
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow (CWE‑20) was identified in several NETGEAR Nighthawk routers. The flaw allows an authenticated administrator to overwrite memory on the router’s stack, enabling unauthorized modification of router software or configuration. This could compromise the integrity of the device, leading to unintended routing policies, loss of network isolation, or deployment of malicious firmware.

Affected Systems

The affected products are NETGEAR Nighthawk routers, including models RAX20, RAX35v2, RAX41, RAX41v2, RAX42, RAX42v2, RAX43, RAX43v2, RAX45, RAX49S, RAX50, RAX50S, RAX50v2, RAX54Sv2, RAX54v2, RAXE450, RAXE500, XR1000, and XR1000v2. Firmware versions susceptible to the vulnerability include V1.0.16.132 and V1.1.4.28, along with earlier builds. Devices marked End‑of‑Support (EoS) such as RAX20, RAX41, RAX42, and RAX45 have ceased receiving security updates, and users are advised to retire or replace them with newer, supported models.

Risk and Exploitability

With a CVSS score of 1.9 and no EPSS data, the vulnerability is considered low severity because it requires an authenticated administrator to trigger the stack overflow. Attackers would need local or remote administrative credentials to exploit the flaw, after which they could modify firmware or router functionality. The CISA KEV catalog does not list this CVE, indicating that advanced persistent threat exploitation is not publicly confirmed. Nonetheless, any compromised administrative session poses a risk of unapproved firmware changes, so prompt patching and strong credential protection remain critical.

Generated by OpenCVE AI on August 11, 2026 at 22:55 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionRAX20 (EoS) 4-Stream AX1800 WiFi 6 RouterEoSRAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router V1.0.16.132 https://www.netgear.com/support/product/rax35v2/ RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi RouterEoSRAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax41v2/ RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi RouterEoSRAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax42v2/ RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.0.16.132 https://www.netgear.com/support/product/rax43/ RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax43v2/ RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi RouterEoSRAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax49s/ RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.16.132 https://www.netgear.com/support/product/rax50/ RAX50S (EoS) Nighthawk AX6 6-Stream AX5400 WiFi 6 RouterEoSRAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.4.28 https://www.netgear.com/support/product/rax50v2/ RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.4.28 https://www.netgear.com/support/product/rax54sv2/ RAX54v2 Nighthawk AX6 6-Stream AX5400 WiFi RouterV1.1.4.28RAXE450 (EoS) Nighthawk AXE10000 Tri-Band WiFi 6E RouterEoSRAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.114 https://www.netgear.com/support/product/raxe500/ XR1000 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000/ XR1000v2 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000v2/ Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


OpenCVE Recommended Actions

  • Update the router to the latest firmware version, such as V1.1.4.28 for RAX43/RAX43v2 or V1.2.14.114 for RAXE500.
  • Enable automatic firmware updates to ensure future patches are applied automatically.
  • For devices that have reached End‑of‑Support, replace them with a newer model that receives ongoing security updates, or remove them from the network.
  • Disallow remote administration or limit administrative access to trusted internal networks.
  • Use strong, unique passwords for all admin accounts and enforce password rotation.

Generated by OpenCVE AI on August 11, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 07:45:00 +0000


Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
Title Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers
First Time appeared Netgear
Netgear rax20
Netgear rax35v2
Netgear rax41
Netgear rax41v2
Netgear rax42
Netgear rax42v2
Netgear rax43
Netgear rax43v2
Netgear rax45
Netgear rax49s
Netgear rax50
Netgear rax50s
Netgear rax50v2
Netgear rax54sv2
Netgear rax54v2
Netgear raxe450
Netgear raxe500
Netgear xr1000
Netgear xr1000v2
Weaknesses CWE-20
CPEs cpe:2.3:a:netgear:rax20:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax35v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax41:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax41v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax42:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax42v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax43:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax43v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax45:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax49s:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax50:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax50s:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax50v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax54sv2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:rax54v2:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:raxe450:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:raxe500:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:xr1000:*:*:*:*:*:*:*:*
cpe:2.3:a:netgear:xr1000v2:*:*:*:*:*:*:*:*
Vendors & Products Netgear
Netgear rax20
Netgear rax35v2
Netgear rax41
Netgear rax41v2
Netgear rax42
Netgear rax42v2
Netgear rax43
Netgear rax43v2
Netgear rax45
Netgear rax49s
Netgear rax50
Netgear rax50s
Netgear rax50v2
Netgear rax54sv2
Netgear rax54v2
Netgear raxe450
Netgear raxe500
Netgear xr1000
Netgear xr1000v2
References
Metrics cvssV4_0

{'score': 1.9, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-08-12T07:36:07.626Z

Reserved: 2026-06-09T02:46:45.370Z

Link: CVE-2026-11736

cve-icon Vulnrichment

Updated: 2026-08-11T17:07:12.282Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:27.653

Modified: 2026-08-28T21:16:15.740

Link: CVE-2026-11736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:15:17Z

Weaknesses
  • CWE-20

    Improper Input Validation