Description
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Published: 2026-09-08
Score: 1.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Router Management UI Denial of Service
Action: Patch Update
AI Analysis

Impact

The vulnerability is an insufficient input validation flaw that permits a network‑adjacent attacker with Wi‑Fi credentials to send malformed input to the router’s management interface, causing it to crash. The crash affects only the user‑interface portion of the router and does not expose configuration data or alter otherwise protected state, so there is no impact on data confidentiality or integrity. Availability of the router’s core services—Wi‑Fi connectivity, routing and DHCP—remains unaffected by this UI crash.

Affected Systems

The flaw applies to NETGEAR routers in the RAX series, specifically the RAX30, RAX35, RAX38, RAX40 and RAXE300 models. Devices that implement automatic firmware updates may already contain the fix. The notified fixed firmware versions are V1.0.9.92 for the RAX30, V1.0.10.72 for the RAX35, V1.0.6.106 for the EoS RAX38 and RAX40, and V1.0.10.72 for the RAXE300. It is advisable to verify the firmware version against the vendor’s support pages.

Risk and Exploitability

The CVSS base score of 1.2 denotes a very low‑severity impact. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. The attack requires the attacker to be on the same local network or otherwise gain Wi‑Fi credentials, meaning it is an in‑network or local threat. Because the failure is limited to the management UI, a successful exploit would only cause a temporary service interruption for the router’s web GUI, without broader network compromise.

Generated by OpenCVE AI on September 10, 2026 at 02:55 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionRAX30 Nighthawk AX5 5-Stream AX2400 WiFi 6 Router V1.0.9.92 https://www.netgear.com/support/product/rax30 RAX35 Nighthawk AX4 4-Stream WiFi 6 Router V1.0.10.72 https://www.netgear.com/support/product/rax35 RAX38 (EoS) Nighthawk AX4 4-Stream AX3000 WiFi Router V1.0.6.106 https://www.netgear.com/support/product/rax38 RAX40 (EoS) Nighthawk AX4 4-Stream WiFi Router V1.0.6.106 https://www.netgear.com/support/product/rax40 RAXE300 Nighthawk AXE7800 Tri-Band WiFi 6E Router V1.0.10.72 https://www.netgear.com/support/product/raxe300 Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


OpenCVE Recommended Actions

  • Update the router to the latest firmware version documented for your model (e.g., V1.0.9.92 for RAX30).
  • If the device is End‑of‑Support, retire it and replace it with a newer NETGEAR model that receives ongoing security updates.
  • Limit access to the router’s management interface by configuring the firewall to allow only trusted IP ranges or by disabling remote management features.

Generated by OpenCVE AI on September 10, 2026 at 02:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear rax30 Firmware
Netgear rax35 Firmware
Netgear rax38 Firmware
Netgear rax40 Firmware
Netgear raxe300 Firmware
CPEs cpe:2.3:h:netgear:rax30:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax35:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax38:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax40:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:raxe300:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax35_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax38_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:raxe300_firmware:*:*:*:*:*:*:*:*
Vendors & Products Netgear rax30 Firmware
Netgear rax35 Firmware
Netgear rax38 Firmware
Netgear rax40 Firmware
Netgear raxe300 Firmware

Thu, 10 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear rax30
Netgear rax35
Netgear rax38
Netgear rax40
Netgear raxe300
Vendors & Products Netgear
Netgear rax30
Netgear rax35
Netgear rax38
Netgear rax40
Netgear raxe300

Wed, 09 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/AU:Y/R:A/V:D/RE:L/U:Amber'}


Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Title Insufficient input validation vulnerability exists in certain NETGEAR RAX Models
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Netgear Rax30 Rax30 Firmware Rax35 Rax35 Firmware Rax38 Rax38 Firmware Rax40 Rax40 Firmware Raxe300 Raxe300 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-09-09T03:55:13.848Z

Reserved: 2026-05-21T17:29:09.097Z

Link: CVE-2026-9216

cve-icon Vulnrichment

Updated: 2026-09-08T18:26:45.607Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:21:18.040

Modified: 2026-09-11T21:20:31.633

Link: CVE-2026-9216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T06:45:12Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow