Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

NETGEAR's Product Security Team has assessed the following product vulnerabilities and provided guidance to address these vulnerabilities in the table below.

Because firmware updates contain security fixes, bug fixes, and new features for your products, we strongly advise you to enable automatic firmware updates on supported devices. For older products, we advise you to download and install new firmware updates as soon as possible or follow the guidance provided for devices that require other remediation steps.

CVE-2026-11814 Command injection vulnerability in some NETGEAR Nighthawk and Orbi routers

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.

Severity: MEDIUM

Acknowledgments: nobodyisnobody

Recommendation:

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

Product Fixed Version
BE9300 Nighthawk WiFi 7 Tri-Band Router V1.0.1.84
MR60 (EoS) Nighthawk Mesh WiFi 6 Router V1.1.8.142
MS60 Nighthawk Mesh WiFi 6 Add-on Satellite V1.1.8.142
R6700AX (EoS) 4-Stream AX1800 WiFi 6 Router V1.0.18.164
RAX10 4-Stream AX1800 WiFi 6 Router V1.0.5.50
RAX120 (EoS) Nighthawk AX12 12-Stream WiFi Router V1.2.10.56
RAX120v2 Nighthawk AX12 12-Stream AX6000 WiFi Router V1.2.10.56
RAX20 (EoS) 4-Stream AX1800 WiFi 6 Router V1.0.17.142
RAX28 (EoS) Nighthawk AX5 5-Stream AX2200 WiFi 6 Router V1.0.14.108
RAX29 Nighthawk AX2400 WiFi 6 Router V1.0.14.108
RAX30 (EoS) Nighthawk AX5 5-Stream AX2400 WiFi 6 Router V1.0.14.108
RAX36S Nighthawk AX4 4-Stream AX3000 WiFi Router V1.0.5.50
RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.0.17.142
RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router V1.0.17.142
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.17.142
RAX70 Nighthawk Tri-band AX8 8-Stream AX6600 WiFi 6 Router V1.0.19.172
RBR760 Orbi Tri-Band Mesh WiFi 6 Router V6.3.8.11
RBS760 Orbi Tri-Band Mesh WiFi 6 Add-on Satellite V6.3.8.11
RS100 Nighthawk WiFi 7 Dual-Band Router V1.0.1.80
RS200 Nighthawk BE6500 WiFi 7 Dual-Band Router V1.0.1.90
RS280 Nighthawk BE9200 WiFi 7 Tri-Band Router V1.0.1.90
RS300 Nighthawk BE9300 WiFi 7 Tri-Band Router V1.0.1.90
RS500 Nighthawk BE12000 WiFi 7 Tri-Band Router V1.0.1.90
RS600 Nighthawk BE18000 WiFi 7 Tri-Band Router V1.0.1.90
RS70 Nighthawk WiFi 7 Dual-Band Router V1.0.1.80
RS90 Nighthawk WiFi 7 Dual-Band Router V1.0.1.80

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

CVE-2026-11739 Command injection vulnerability in some NETGEAR Nighthawk devices

A command injection vulnerability in affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.

Severity: MEDIUM

Acknowledgments: fluorescent

Recommendation:

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

Product Fixed Version
MR60 (EoS) Nighthawk Mesh WiFi 6 Router V1.1.8.142
MR70 (EoS) Nighthawk Mesh WiFi 6 Router V1.0.4.48
MR90 Nighthawk Tri-band Mesh WiFi 6E Router V1.0.2.46
MS60 Nighthawk Mesh WiFi 6 Add-on Satellite V1.1.8.142
MS70 Nighthawk Mesh WiFi 6 Add-on Satellite V1.0.4.48
MS90 Nighthawk Tri-band Mesh WiFi 6E Add-on Satellite V1.0.2.46
RAX20 (EoS) 4-Stream AX1800 WiFi 6 Router V1.0.17.142
RAX200 (EoS) Nighthawk Tri-Band AX12 12-Stream WiFi Router V1.0.11.148
RAX35 (EoS) Nighthawk AX4 4-Stream WiFi 6 Router V1.0.17.142
RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router V1.0.17.142
RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36
RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36
RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router V1.0.17.142
RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.6.36
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36
RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36
RAX54S Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36
RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36
RAX80 (EoS) Nighthawk AX8 8-Stream WiFi Router V1.0.11.148
RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.110
RS700 Nighthawk BE19000 WiFi 7 Tri-Band Router V1.0.9.6
XR1000 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22
XR1000v2 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

CVE-2026-11737 Insufficient input validation vulnerability in some NETGEAR Nighthawk devices

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to device software and functionality.

Severity: MEDIUM

Acknowledgments: Matt19

Recommendation:

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

Product Fixed Version
RAX20 (EoS) 4-Stream AX1800 WiFi 6 Router V1.0.18.144
RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36
RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36
RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router V1.0.17.142
RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.6.36
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36
RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36
RAX54S Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36
RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

CVE-2026-11738 Insufficient input validation in some NETGEAR Nighthawk routers

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

Severity: MEDIUM

Acknowledgments: fxc233

Affected Products:

Recommendation:

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

Product Fixed Version
R7000 (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router EOS
RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.114
RS700 Nighthawk BE19000 WiFi 7 Tri-Band Router V1.0.7.66

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

CVE-2026-9214 Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device.

Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

Severity: MEDIUM

Affected Products:

Recommendation:

R7000 has reached its End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

CVE-2026-11735 Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models

A stack-based buffer overflow vulnerability in affected NETGEAR models allowing an authenticated admin user to make unauthorized modifications to the router's software and functionality.

Severity: LOW

Acknowledgments: SmallS

Recommendation:

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

Product Fixed Version
R7000 (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router EOS
RAX20 (EoS) 4-Stream AX1800 WiFi 6 Router EOS
RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router V1.0.16.132
RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router EOS
RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.4.28
RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router EOS
RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.4.28
RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.0.16.132
RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.4.28
RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router EOS
RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.4.28
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.16.132
RAX50S (EoS) Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.16.132
RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.4.28
RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.4.28
RAX54v2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.4.28
RAXE450 (EoS) Nighthawk AXE10000 Tri-Band WiFi 6E Router EOS
RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.114
XR1000 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22
XR1000v2 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

CVE-2026-11736 Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers

A stack-based buffer overflow vulnerability in affected NETGEAR models allows an authenticated admin user to make unauthorized modification to router's software and functionality.

Severity: LOW

Acknowledgments: SmallS

Recommendation:

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

Product Fixed Version
RAX20 (EoS) 4-Stream AX1800 WiFi 6 Router EoS
RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router V1.0.16.132
RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router EoS
RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.4.28
RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router EoS
RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.4.28
RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.0.16.132
RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.4.28
RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router EoS
RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.4.28
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.16.132
RAX50S (EoS) Nighthawk AX6 6-Stream AX5400 WiFi 6 Router EoS
RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.4.28
RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.4.28
RAX54v2Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.4.28
RAXE450 (EoS) Nighthawk AXE10000 Tri-Band WiFi 6E Router EoS
RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.114
XR1000 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22
XR1000v2 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

CVE-2026-11733 Buffer overflow vulnerability in some NETGEAR Nighthawk routers

A buffer overflow vulnerability in the listed NETGEAR models allows an administrator to temporarily interrupt the normal operation of the affected device.

Severity: LOW

Acknowledgments: tmotfl

Recommendation:

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

Product Fixed Version
RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36
RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36
RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.6.36
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36
RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36
RAX54S Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36
RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

CVE-2026-11734 Buffer overflow vulnerability in some NETGEAR Nighthawk devices.

A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.

Severity: LOW

Acknowledgments: tmotfl

Recommendation:

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in:

Product Fixed Version
MR70 (EoS) Nighthawk Mesh WiFi 6 Router V1.0.4.48
MR90 Nighthawk Tri-band Mesh WiFi 6E Router V1.0.2.46
MS70 Nighthawk Mesh WiFi 6 Add-on Satellite V1.0.4.48
MS90 Nighthawk Tri-band Mesh WiFi 6E Add-on Satellite V1.0.2.46
RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36
RAX41v2 Nighthawk AX5 5-Stream AX3600 WiFi Router V1.1.6.36
RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX42v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX43v2 Nighthawk AX5 5-Stream AX4200 WiFi Router V1.1.6.36
RAX49S Nighthawk AX6 6-Stream AX5300 WiFi Router V1.1.6.36
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36
RAX50v2 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.1.6.36
RAX54S Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36
RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36

Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

Disclaimer: This document is provided on an "as is" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information in the document or materials linked to the document is at your own risk. NETGEAR reserves the right to change or update this document at any time. NETGEAR expects to update this document as new information becomes available.

The above-listed vulnerabilities remain if you do not complete all recommended steps. NETGEAR is not responsible for any consequences that could have been avoided by following the recommendations in this notification.

Last Updated:08/18/2026 | Article ID: 000070887

This article applies to:

Recently Viewed Articles

    Read this article in another language:

    Read this article in another language:

    Our team is here to help!

    Phone
    Chat
    Email