Description
A command injection vulnerability in certain affected NETGEAR Nighthawk
devices allows a network-adjacent attacker with the ability to intercept
and modify local network traffic (attacker in the middle) to compromise
the confidentiality and integrity of the affected device.
Published: 2026-08-11
Score: 4.9 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection vulnerability (CWE‑78) exists in certain NETGEAR Nighthawk routers, allowing a network‑adjacent attacker to execute arbitrary commands on the affected devices. The exploitation requires the attacker to intercept and modify local network traffic, compromising the confidential data stored on the router or altering its configuration, leading to a loss of integrity. The CVSS score of 4.9 indicates a moderate risk, but the potential impact could be significant if the device is used for further network attacks.

Affected Systems

Affected products include the NETGEAR Nighthawk line such as the MR60 Mesh WiFi 6 Router, MR70 Mesh WiFi 6 Router, MR90 Tri‑band Mesh WiFi 6E Router, the MS60 and MS70 Mesh WiFi 6 add‑on satellites, MS90 Tri‑band Mesh WiFi 6E add‑on satellite, the RAX20 4‑Stream AX1800 WiFi 6 Router, RAX200 Tri‑band AX12 12‑Stream WiFi Router, RAX35 and RAX35v2 AX4 4‑Stream WiFi 6/AX3000 routers, RAX41, RAX41v2, RAX42, RAX42v2, RAX43, RAX43v2 all AX5 5‑Stream routers, the RAX45 AX6 6‑Stream AX4300 router, RAX49S AX6 6‑Stream AX5300 router, RAX50 and RAX50v2 AX6 6‑Stream AX5400 routers, RAX54S and RAX54Sv2 AX6 6‑Stream AX5400 routers, RAX80 AX8 8‑Stream router, RAXE500 AX12 12‑Stream AXE11000 Tri‑band router, the RS700 BE19000 WiFi 7 Tri‑band router, and the XR1000 XR1000v2 WiFi 6 Pro Gaming routers. Many of these models are marked End‑of‑Support with no further updates planned, and the fixed versions are listed from V1.0.11.148 to V1.2.14.110 as noted in the vendor advisory.

Risk and Exploitability

Because the vulnerability requires active packet sniffing and modification on the local network, the attack surface is limited to network‑adjacent actors, such as compromised local clients or devices that can facilitate a man‑in‑the‑middle attack. The CVSS score of 4.9 and EPSS score of 1% suggest the exploitation likelihood is moderate to low; the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Nevertheless, once compromised, the attacker can alter router configurations or capture sensitive traffic, potentially enabling further network compromise.

Generated by OpenCVE AI on August 13, 2026 at 02:50 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionMR60 (EoS) Nighthawk Mesh WiFi 6 Router V1.1.8.142 https://www.netgear.com/support/product/mr60/ MR70 (EoS) Nighthawk Mesh WiFi 6 Router V1.0.4.48 https://www.netgear.com/support/product/mr70/ MR90 Nighthawk Tri-band Mesh WiFi 6E Router V1.0.2.46 https://www.netgear.com/support/product/mr90/ MS60 Nighthawk Mesh WiFi 6 Add-on Satellite V1.1.8.142 https://www.netgear.com/support/product/ms60/ MS70 Nighthawk Mesh WiFi 6 Add-on Satellite V1.0.4.48 https://www.netgear.com/support/product/ms70/ MS90 Nighthawk Tri-band Mesh WiFi 6E Add-on Satellite V1.0.2.46 https://www.netgear.com/support/product/ms90/ RAX20 (EoS) 4-Stream AX1800 WiFi 6 Router V1.0.17.142 https://www.netgear.com/support/product/rax20/ RAX200 (EoS) Nighthawk Tri-Band AX12 12-Stream WiFi Router V1.0.11.148 https://www.netgear.com/support/product/rax200/ RAX35 (EoS) Nighthawk AX4 4-Stream WiFi 6 Router V1.0.17.142 https://www.netgear.com/support/product/rax35/ RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router V1.0.17.142 https://www.netgear.com/support/product/rax35v2/ RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax41/ RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax41v2/ RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax42/ RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax42v2/ RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax43/ RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax43v2/ RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router V1.0.17.142 https://www.netgear.com/support/product/rax45/ RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax49s/ RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36 https://www.netgear.com/support/product/rax50/ RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36 https://www.netgear.com/support/product/rax50v2/ RAX54S Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax54s/ RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax54sv2/ RAX80 (EoS) Nighthawk AX8 8-Stream WiFi Router V1.0.11.148 https://www.netgear.com/support/product/rax80/ RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.110 https://www.netgear.com/support/product/raxe500/ RS700 Nighthawk BE19000 WiFi 7 Tri-Band Router V1.0.9.6 https://www.netgear.com/support/product/rs700/ XR1000 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000/ XR1000v2 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000v2/ Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


OpenCVE Recommended Actions

  • Upgrade the firmware to the latest version supported by each device following the vendor’s advisory.
  • If the device is End‑of‑Support or cannot be updated, disconnect it from the network or replace it with a supported model to prevent exploitation.
  • Ensure that only trusted devices can access the local network or use VLAN segmentation to isolate sensitive traffic, reducing opportunities for a man‑in‑the‑middle actor.

Generated by OpenCVE AI on August 13, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 08:15:00 +0000


Tue, 11 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear mr60
Netgear mr70
Netgear mr90
Netgear ms60
Netgear ms70
Netgear ms90
Netgear rax20
Netgear rax200
Netgear rax35
Netgear rax35v2
Netgear rax41
Netgear rax41v2
Netgear rax42
Netgear rax42v2
Netgear rax43
Netgear rax43v2
Netgear rax45
Netgear rax49s
Netgear rax50
Netgear rax50v2
Netgear rax54s
Netgear rax54sv2
Netgear rax80
Netgear raxe500
Netgear rs700
Netgear xr1000
Netgear xr1000v2
Vendors & Products Netgear
Netgear mr60
Netgear mr70
Netgear mr90
Netgear ms60
Netgear ms70
Netgear ms90
Netgear rax20
Netgear rax200
Netgear rax35
Netgear rax35v2
Netgear rax41
Netgear rax41v2
Netgear rax42
Netgear rax42v2
Netgear rax43
Netgear rax43v2
Netgear rax45
Netgear rax49s
Netgear rax50
Netgear rax50v2
Netgear rax54s
Netgear rax54sv2
Netgear rax80
Netgear raxe500
Netgear rs700
Netgear xr1000
Netgear xr1000v2

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
Title Command injection vulnerability in some NETGEAR Nighthawk devices
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 4.9, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-08-12T07:44:33.040Z

Reserved: 2026-06-09T02:46:48.152Z

Link: CVE-2026-11739

cve-icon Vulnrichment

Updated: 2026-08-11T19:24:28.548Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:28.260

Modified: 2026-08-28T21:16:15.740

Link: CVE-2026-11739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T03:00:09Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')