CVE-2026-11737
Estado: AnalizadaMedia (4.3)—
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (13)
Netgear — Rax20 FirmwareNetgear — Rax41 FirmwareNetgear — Rax41v2 FirmwareNetgear — Rax42 FirmwareNetgear — Rax42v2 FirmwareNetgear — Rax43 FirmwareNetgear — Rax43v2 FirmwareNetgear — Rax45 FirmwareNetgear — Rax49s FirmwareNetgear — Rax50 FirmwareNetgear — Rax50v2 FirmwareNetgear — Rax54s FirmwareNetgear — Rax54sv2 Firmware
CWE
- CWE-20
Referencias
- https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory
- https://www.netgear.com/support/product/rax20/
- https://www.netgear.com/support/product/rax41/
- https://www.netgear.com/support/product/rax41v2/
- https://www.netgear.com/support/product/rax42/
- https://www.netgear.com/support/product/rax42v2/
- https://www.netgear.com/support/product/rax43/
- https://www.netgear.com/support/product/rax43v2/
- https://www.netgear.com/support/product/rax45/
- https://www.netgear.com/support/product/rax49s/
- https://www.netgear.com/support/product/rax50/
- https://www.netgear.com/support/product/rax50v2/
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-11737",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-11737",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-08-11T19:25:03.471360Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 0.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "USER",
"baseScore": 4.3,
"Automatable": "NO",
"attackVector": "ADJACENT",
"baseSeverity": "MEDIUM",
"valueDensity": "DIFFUSE",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber",
"exploitMaturity": "UNREPORTED",
"providerUrgency": "AMBER",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "HIGH",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "LOW",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
"affectedData": [
{
"vendor": "NETGEAR",
"product": "RAX20",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.0.18.144",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX41",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX41v2",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX42",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX42v2",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX43",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX43v2",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX45",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.0.17.142",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX49S",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX50",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX50v2",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX54S",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "NETGEAR",
"product": "RAX54Sv2",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1.1.6.36",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-11T16:17:27.917",
"references": [
{
"url": "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
"tags": [
"Vendor Advisory"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax20/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax41/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax41v2/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax42/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax42v2/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax43/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax43v2/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax45/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax49s/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax50/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
},
{
"url": "https://www.netgear.com/support/product/rax50v2/",
"tags": [
"Product"
],
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insufficient input validation vulnerability in the listed \nNETGEAR models allows authenticated administrators connected to the \nlocal network to make unauthorized modification to the device software and \nfunctionality."
}
],
"lastModified": "2026-09-09T02:59:15.787",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax20_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "459255C7-BB1F-49E5-ADCC-B95D1AF52CBE",
"versionEndExcluding": "1.0.18.144"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax20:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7038703C-C79D-4DD4-8B16-E1A5FC6694C0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax41_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46D0F9BA-4A9C-4413-AD48-860D211186D2",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax41:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C52C7C17-08C5-47CE-A5D5-640C6B9DB82C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax41v2_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BEC93BCF-E89C-49A9-9631-1666E6FF4E21",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax41v2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "138DD7E4-528F-4984-ACD7-E18379C4FF7C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax42_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AD5DAFC-6427-452B-ABB0-F15A40AAE70A",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax42:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D83182AB-E726-4371-B092-FA1920408FED"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax42v2_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "23B8F4EF-7E41-4686-9138-77FE95114F8B",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax42v2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D61EA1E9-FB8C-4E79-8A07-7B5E79DCB70A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax43_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F75B7F3E-E75C-46BA-B71C-EDF1150D944A",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax43:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "178BB386-F66C-4CE8-9283-37D22B304691"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax43v2_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01763B66-6177-4EDC-BD12-54D931DFDB2F",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax43v2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6E165736-5E8D-4DDB-B157-99723FE20BD2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax45_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C93981C6-FF9B-46D2-836A-CFAF47EC87FF",
"versionEndExcluding": "1.0.17.142"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax45:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4B08BD69-CDCC-4CEB-B887-4E47D2B45D26"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax49s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAC35BB2-E9D2-4097-BA74-3FDCFD83741B",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax49s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "85511EF7-8F04-4DB7-8CF3-2F888A0A94C5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D1D4D059-7AC9-4AD2-BB12-D8250FD8068F",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax50:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C430976E-24C0-4EA7-BF54-F9C188AB9C01"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax50v2_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "92ED39F8-F270-46EA-8947-F855FEFD5CF5",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax50v2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "59381950-4DC4-4FD7-B3DB-D950DDA5C591"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax54s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BF51DD4-8A10-49A9-9E70-0CE25092118B",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax54s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C8B501CB-118F-4AA6-B822-E83C0D6269C3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netgear:rax54sv2_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83DB8165-F9DC-4086-91AF-9C4298FECBCC",
"versionEndExcluding": "1.1.6.36"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netgear:rax54sv2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B9FCC230-8A49-4C8C-BB53-DD703996F4DA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "a2826606-91e7-4eb6-899e-8484bd4575d5"
}