Description
Insufficient input validation vulnerability in the NETGEAR R7000 models
allows authenticated administrators connected to the local network to
make unauthorized modification to router software and functionality.
Published: 2026-08-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient input validation in the NETGEAR R7000 models permits an authenticated administrator on the local network to transmit malformed input that is accepted by the router’s software, enabling the attacker to alter or add configuration settings. This may result in unauthorized changes to routing rules, firewall policies, or other critical functionality, potentially compromising the integrity of the network infrastructure. The weakness is identified as CWE-20.

Affected Systems

The affected systems are all NETGEAR R7000 routers. Specific firmware versions are not enumerated, and the product is currently listed as having reached End‑of‑Support with no forthcoming security updates.

Risk and Exploitability

The CVSS score is 4.3, indicating moderate severity. Because the exploit requires local administrative authentication and there is no publicly available exploit code, the likelihood of exploitation is limited to insiders or attackers who have compromised local credentials. The EPSS score is not available and the vulnerability is not included in CISA’s KEV catalog, suggesting it is not widely exploited. The attack vector is local, and mitigation depends on disabling or securing administrative access.

Generated by OpenCVE AI on August 11, 2026 at 23:05 UTC.

Remediation

Vendor Solution

R7000 has reached its End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


OpenCVE Recommended Actions

  • Replace the NETGEAR R7000 router with a newer device that receives security updates.
  • Restrict local management access to trusted personnel and enforce strong authentication.
  • Disable or block the router’s web management interface from the LAN and monitor logs for abnormal configuration changes.

Generated by OpenCVE AI on August 11, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 07:45:00 +0000


Tue, 11 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear r7000
Vendors & Products Netgear
Netgear r7000

Tue, 11 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Title Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device.
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-08-12T07:14:57.379Z

Reserved: 2026-05-21T17:29:07.021Z

Link: CVE-2026-9214

cve-icon Vulnrichment

Updated: 2026-08-11T17:03:16.013Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:40.490

Modified: 2026-08-28T21:16:15.740

Link: CVE-2026-9214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T23:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation