Netgear
Netgear Rax20 Firmware: vulnerabilities and CVEs
Netgear Rax20 Firmware has 46 published vulnerabilities, 10 of them in the last 12 months. 12 are rated critical and 0 are listed by CISA as actively exploited.
CVEs46
Last 12 months10
Critical12
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11814 | Medium (4.9) | 0.91% | — | Aug 11, 2026 | A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality… |
| CVE-2026-11739 | Medium (4.9) | 1.1% | — | Aug 11, 2026 | A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise… |
| CVE-2026-11738 | Medium (4.3) | 0.27% | — | Aug 11, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. |
| CVE-2026-11737 | Medium (4.3) | 0.22% | — | Aug 11, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality. |
| CVE-2026-11736 | Low (1.9) | 0.51% | — | Aug 11, 2026 | A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. |
| CVE-2026-11735 | Low (1.9) | 0.51% | — | Aug 11, 2026 | A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. |
| CVE-2026-9210 | Medium (4.9) | 0.35% | — | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. |
| CVE-2026-0418 | Medium (4.3) | 0.24% | — | Jun 9, 2026 | Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. |
| CVE-2026-0417 | Medium (4.3) | 0.23% | — | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. |
| CVE-2026-0410 | Low (1.9) | 0.22% | — | Jun 9, 2026 | Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality. |
| CVE-2021-34983 | Medium (6.5) | 0.33% | — | May 7, 2024 | NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected… |
| CVE-2021-34982 | High (8.8) | 0.58% | — | May 7, 2024 | NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple… |
| CVE-2022-27647 | High (8) | 1.5% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability,… |
| CVE-2022-27645 | High (8.8) | 1.3% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists… |
| CVE-2022-27642 | High (8.8) | 0.88% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The… |
| CVE-2021-45676 | Medium (4.8) | 0.47% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.5.126, RAX20 before 1.0.2.82, RAX80 before 1.0.5.126, RAX15 before 1.0.2.82, and RAX75 before 1.0.5.126. |
| CVE-2021-45674 | Medium (4.8) | 0.42% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX75 before… |
| CVE-2021-45671 | Medium (4.8) | 0.42% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX80 before 1.0.1.62, EX7500 before 1.0.0.72, R7900 before 1.0.4.38, R8000 before 1.0.4.68, RAX200 before 1.0.4.120, RBS40V before… |
| CVE-2021-45670 | Medium (4.8) | 0.42% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7000 before… |
| CVE-2021-45669 | Medium (4.8) | 0.42% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.3.106, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, MS60 before 1.0.6.110, RAX15 before… |
| CVE-2021-45668 | Medium (4.8) | 0.42% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500… |
| CVE-2021-45667 | Medium (4.8) | 0.42% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7960P before… |
| CVE-2021-45647 | High (7.5) | 1.3% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EAX80 before 1.0.1.62, EX7000 before 1.0.1.104, R6120 before 1.0.0.76, R6220 before 1.1.0.110, R6230 before 1.1.0.110, R6260… |
| CVE-2021-45639 | Medium (6.1) | 0.60% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by reflected XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.32, EAX80 before 1.0.1.62, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7000 before 1.0.1.104, EX7500… |
| CVE-2021-45622 | Critical (9.8) | 2.4% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX7500 before 1.0.0.74,… |
| CVE-2021-45621 | Critical (9.8) | 2.0% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX3700 before 1.0.0.94,… |
| CVE-2021-45620 | Critical (9.8) | 2.0% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, LAX20 before 1.1.6.28,… |
| CVE-2021-45617 | Critical (9.8) | 2.1% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX7500 before 1.0.0.72, R6400 before 1.0.1.68,… |
| CVE-2021-45616 | Critical (9.8) | 2.0% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2.18.2, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116,… |
| CVE-2021-45614 | Critical (9.8) | 2.0% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116,… |