Description
Insufficient input validation vulnerability in the NETGEAR R7000 models
allows authenticated administrators connected to the local network to
make unauthorized modification to router software and functionality.
Published: 2026-08-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of router software and functionality
Action: Retire Device
AI Analysis

Impact

Insufficient input validation in the NETGEAR R7000 models permits an authenticated administrator on the local network to transmit malformed input that is accepted by the router’s software, enabling the attacker to alter or add configuration settings. This may result in unauthorized changes to routing rules, firewall policies, or other critical functionality, potentially compromising the integrity of the network infrastructure. The weakness is identified as CWE-20.

Affected Systems

The affected systems are all NETGEAR R7000 routers. Specific firmware versions are not enumerated, and the product is currently listed as having reached End‑of‑Support with no forthcoming security updates.

Risk and Exploitability

The CVSS score is 4.3, indicating moderate severity. Because the exploit requires local administrative authentication and there is no publicly available exploit code, the likelihood of exploitation is limited to insiders or attackers who have compromised local credentials. The EPSS score is not available and the vulnerability is not included in CISA’s KEV catalog, suggesting it is not widely exploited. The attack vector is local, and mitigation depends on disabling or securing administrative access.

Generated by OpenCVE AI on August 11, 2026 at 23:05 UTC.

Remediation

Vendor Solution

R7000 has reached its End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


OpenCVE Recommended Actions

  • Replace the NETGEAR R7000 router with a newer device that receives security updates.
  • Restrict local management access to trusted personnel and enforce strong authentication.
  • Disable or block the router’s web management interface from the LAN and monitor logs for abnormal configuration changes.

Generated by OpenCVE AI on August 11, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Netgear r7000 Firmware
CPEs cpe:2.3:h:netgear:r7000:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r7000_firmware:-:*:*:*:*:*:*:*
Vendors & Products Netgear r7000 Firmware
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Wed, 12 Aug 2026 07:45:00 +0000


Tue, 11 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear r7000
Vendors & Products Netgear
Netgear r7000

Tue, 11 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Title Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device.
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber'}


Subscriptions

Netgear R7000 R7000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-08-12T07:14:57.379Z

Reserved: 2026-05-21T17:29:07.021Z

Link: CVE-2026-9214

cve-icon Vulnrichment

Updated: 2026-08-11T17:03:16.013Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T16:17:40.490

Modified: 2026-09-09T02:59:29.410

Link: CVE-2026-9214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T23:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation