Impact
The vulnerability is an insufficient input validation flaw that permits a network‑adjacent attacker with Wi‑Fi credentials to send malformed input to the router’s management interface, causing it to crash. The crash affects only the user‑interface portion of the router and does not expose configuration data or alter otherwise protected state, so there is no impact on data confidentiality or integrity. Availability of the router’s core services—Wi‑Fi connectivity, routing and DHCP—remains unaffected by this UI crash.
Affected Systems
The flaw applies to NETGEAR routers in the RAX series, specifically the RAX30, RAX35, RAX38, RAX40 and RAXE300 models. Devices that implement automatic firmware updates may already contain the fix. The notified fixed firmware versions are V1.0.9.92 for the RAX30, V1.0.10.72 for the RAX35, V1.0.6.106 for the EoS RAX38 and RAX40, and V1.0.10.72 for the RAXE300. It is advisable to verify the firmware version against the vendor’s support pages.
Risk and Exploitability
The CVSS base score of 1.2 denotes a very low‑severity impact. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. The attack requires the attacker to be on the same local network or otherwise gain Wi‑Fi credentials, meaning it is an in‑network or local threat. Because the failure is limited to the management UI, a successful exploit would only cause a temporary service interruption for the router’s web GUI, without broader network compromise.
OpenCVE Enrichment