---
id: CVE-2026-11739
title: |-
  A command injection vulnerability in certain affected NETGEAR Nighthawk 
  devices allows a network-adjacent attacker with the ability to intercept
   and modify local network traffic (attacker in the middle) to compromise
   the confidentiali…
summary: |-
  A command injection vulnerability in certain affected NETGEAR Nighthawk 
  devices allows a network-adjacent attacker with the ability to intercept
   and modify local network traffic (attacker in the middle) to compromise
   the confidentiali…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-78
vendor: netgear
product: ms90_firmware
affected:
  - ms90_firmware < 1.0.2.46
  - rax20_firmware < 1.0.17.142
  - rax200_firmware < 1.0.11.148
  - rax35_firmware < 1.0.17.142
  - rax35v2_firmware < 1.0.17.142
  - rax41_firmware < 1.1.6.36
  - rax41v2_firmware < 1.1.6.36
  - rax42_firmware < 1.1.6.36
  - rax42v2_firmware < 1.1.6.36
  - rax43_firmware < 1.1.6.36
  - rax43v2_firmware < 1.1.6.36
  - rax45_firmware < 1.0.17.142
  - rax49s_firmware < 1.1.6.36
  - rax50_firmware < 1.1.6.36
  - rax50v2_firmware < 1.1.6.36
  - rax54s_firmware < 1.1.6.36
  - rax54sv2_firmware < 1.1.6.36
  - rax80_firmware < 1.0.11.148
  - raxe500_firmware < 1.2.14.110
  - rs700_firmware < 1.0.9.6
  - xr1000_firmware < 1.1.0.22
  - xr1000v2_firmware < 1.1.0.22
  - mr60_firmware < 1.1.8.142
  - mr70_firmware < 1.0.4.48
  - mr90_firmware < 1.0.2.46
  - ms60_firmware < 1.1.8.142
  - ms70_firmware < 1.0.4.48
patched:
  - ms90_firmware 1.0.2.46
  - rax20_firmware 1.0.17.142
  - rax200_firmware 1.0.11.148
  - rax35_firmware 1.0.17.142
  - rax35v2_firmware 1.0.17.142
  - rax41_firmware 1.1.6.36
  - rax41v2_firmware 1.1.6.36
  - rax42_firmware 1.1.6.36
  - rax42v2_firmware 1.1.6.36
  - rax43_firmware 1.1.6.36
  - rax43v2_firmware 1.1.6.36
  - rax45_firmware 1.0.17.142
  - rax49s_firmware 1.1.6.36
  - rax50_firmware 1.1.6.36
  - rax50v2_firmware 1.1.6.36
  - rax54s_firmware 1.1.6.36
  - rax54sv2_firmware 1.1.6.36
  - rax80_firmware 1.0.11.148
  - raxe500_firmware 1.2.14.110
  - rs700_firmware 1.0.9.6
  - xr1000_firmware 1.1.0.22
  - xr1000v2_firmware 1.1.0.22
  - mr60_firmware 1.1.8.142
  - mr70_firmware 1.0.4.48
  - mr90_firmware 1.0.2.46
  - ms60_firmware 1.1.8.142
  - ms70_firmware 1.0.4.48
published: '2026-08-11'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T02:59:22.507'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11739'
references:
  - url: 'https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/mr60/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/mr70/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/mr90/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/ms60/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/ms70/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/ms90/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax20/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax200/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax35/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax35v2/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax41/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax41v2/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax42/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax42v2/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax43/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax43v2/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax45/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax49s/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax50/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax50v2/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax80/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/raxe500/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs700/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/xr1000/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/xr1000v2/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
tags:
  - nvd
epss: 0.01068
epssPercentile: 0.63354
ingestedAt: '2026-08-29T19:41:14.518Z'
---

## Overview

A command injection vulnerability in certain affected NETGEAR Nighthawk 
devices allows a network-adjacent attacker with the ability to intercept
 and modify local network traffic (attacker in the middle) to compromise
 the confidentiality and integrity of the affected device.

## Affected

- `ms90_firmware < 1.0.2.46`
- `rax20_firmware < 1.0.17.142`
- `rax200_firmware < 1.0.11.148`
- `rax35_firmware < 1.0.17.142`
- `rax35v2_firmware < 1.0.17.142`
- `rax41_firmware < 1.1.6.36`
- `rax41v2_firmware < 1.1.6.36`
- `rax42_firmware < 1.1.6.36`
- `rax42v2_firmware < 1.1.6.36`
- `rax43_firmware < 1.1.6.36`
- `rax43v2_firmware < 1.1.6.36`
- `rax45_firmware < 1.0.17.142`
- `rax49s_firmware < 1.1.6.36`
- `rax50_firmware < 1.1.6.36`
- `rax50v2_firmware < 1.1.6.36`
- `rax54s_firmware < 1.1.6.36`
- `rax54sv2_firmware < 1.1.6.36`
- `rax80_firmware < 1.0.11.148`
- `raxe500_firmware < 1.2.14.110`
- `rs700_firmware < 1.0.9.6`
- `xr1000_firmware < 1.1.0.22`
- `xr1000v2_firmware < 1.1.0.22`
- `mr60_firmware < 1.1.8.142`
- `mr70_firmware < 1.0.4.48`
- `mr90_firmware < 1.0.2.46`
- `ms60_firmware < 1.1.8.142`
- `ms70_firmware < 1.0.4.48`

## Remediation

Upgrade past the affected range:

- `ms90_firmware 1.0.2.46`
- `rax20_firmware 1.0.17.142`
- `rax200_firmware 1.0.11.148`
- `rax35_firmware 1.0.17.142`
- `rax35v2_firmware 1.0.17.142`
- `rax41_firmware 1.1.6.36`
- `rax41v2_firmware 1.1.6.36`
- `rax42_firmware 1.1.6.36`
- `rax42v2_firmware 1.1.6.36`
- `rax43_firmware 1.1.6.36`
- `rax43v2_firmware 1.1.6.36`
- `rax45_firmware 1.0.17.142`
- `rax49s_firmware 1.1.6.36`
- `rax50_firmware 1.1.6.36`
- `rax50v2_firmware 1.1.6.36`
- `rax54s_firmware 1.1.6.36`
- `rax54sv2_firmware 1.1.6.36`
- `rax80_firmware 1.0.11.148`
- `raxe500_firmware 1.2.14.110`
- `rs700_firmware 1.0.9.6`
- `xr1000_firmware 1.1.0.22`
- `xr1000v2_firmware 1.1.0.22`
- `mr60_firmware 1.1.8.142`
- `mr70_firmware 1.0.4.48`
- `mr90_firmware 1.0.2.46`
- `ms60_firmware 1.1.8.142`
- `ms70_firmware 1.0.4.48`
