Description
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Published: 2026-09-08
Score: 1.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionRAX30 Nighthawk AX5 5-Stream AX2400 WiFi 6 Router V1.0.9.92 https://www.netgear.com/support/product/rax30 RAX35 Nighthawk AX4 4-Stream WiFi 6 Router V1.0.10.72 https://www.netgear.com/support/product/rax35 RAX38 (EoS) Nighthawk AX4 4-Stream AX3000 WiFi Router V1.0.6.106 https://www.netgear.com/support/product/rax38 RAX40 (EoS) Nighthawk AX4 4-Stream WiFi Router V1.0.6.106 https://www.netgear.com/support/product/rax40 RAXE300 Nighthawk AXE7800 Tri-Band WiFi 6E Router V1.0.10.72 https://www.netgear.com/support/product/raxe300 Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear rax30 Firmware
Netgear rax35 Firmware
Netgear rax38 Firmware
Netgear rax40 Firmware
Netgear raxe300 Firmware
CPEs cpe:2.3:h:netgear:rax30:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax35:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax38:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax40:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:raxe300:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax35_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax38_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:raxe300_firmware:*:*:*:*:*:*:*:*
Vendors & Products Netgear rax30 Firmware
Netgear rax35 Firmware
Netgear rax38 Firmware
Netgear rax40 Firmware
Netgear raxe300 Firmware

Thu, 10 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear rax30
Netgear rax35
Netgear rax38
Netgear rax40
Netgear raxe300
Vendors & Products Netgear
Netgear rax30
Netgear rax35
Netgear rax38
Netgear rax40
Netgear raxe300

Wed, 09 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/AU:Y/R:A/V:D/RE:L/U:Amber'}


Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Title Insufficient input validation vulnerability exists in certain NETGEAR RAX Models
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Netgear Rax30 Rax30 Firmware Rax35 Rax35 Firmware Rax38 Rax38 Firmware Rax40 Rax40 Firmware Raxe300 Raxe300 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-09-09T03:55:13.848Z

Reserved: 2026-05-21T17:29:09.097Z

Link: CVE-2026-9216

cve-icon Vulnrichment

Updated: 2026-09-08T18:26:45.607Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:21:18.040

Modified: 2026-09-11T21:20:31.633

Link: CVE-2026-9216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T06:45:12Z

Weaknesses