An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
History

Thu, 10 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear rax30
Netgear rax35
Netgear rax38
Netgear rax40
Netgear raxe300
Vendors & Products Netgear
Netgear rax30
Netgear rax35
Netgear rax38
Netgear rax40
Netgear raxe300

Wed, 09 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/AU:Y/R:A/V:D/RE:L/U:Amber'}


Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
Title Insufficient input validation vulnerability exists in certain NETGEAR RAX Models
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published: 2026-09-08T17:09:12.157Z

Updated: 2026-09-09T03:55:13.848Z

Reserved: 2026-05-21T17:29:09.097Z

Link: CVE-2026-9216

cve-icon Vulnrichment

Updated: 2026-09-08T18:26:45.607Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:21:18.040

Modified: 2026-09-09T04:20:27.800

Link: CVE-2026-9216

cve-icon Redhat

No data.