---
id: CVE-2026-11814
title: >-
  A command injection vulnerability in the listed NETGEAR models allows a
  network-adjacent attacker with the ability to intercept and modify local
  network traffic (attacker-in-the-middle) to compromise the confidentiality and
  integrity of …
summary: >-
  A command injection vulnerability in the listed NETGEAR models allows a
  network-adjacent attacker with the ability to intercept and modify local
  network traffic (attacker-in-the-middle) to compromise the confidentiality and
  integrity of …
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-295
  - CWE-77
vendor: netgear
product: be9300_firmware
affected:
  - be9300_firmware < 1.0.1.84
  - mr60_firmware < 1.1.8.142
  - ms60_firmware < 1.1.8.142
  - r6700ax_firmware < 1.0.18.164
  - rax10_firmware < 1.0.5.50
  - rax120_firmware < 1.2.10.56
  - rax120v2_firmware < 1.2.10.56
  - rax20_firmware < 1.0.17.142
  - rax28_firmware < 1.0.14.108
  - rax29_firmware < 1.0.14.108
  - rax30_firmware < 1.0.14.108
  - rax36s_firmware < 1.0.5.50
  - rax43_firmware < 1.0.17.142
  - rax45_firmware < 1.0.17.142
  - rax50_firmware < 1.0.17.142
  - rax70_firmware < 1.0.19.172
  - rbr760_firmware < 6.3.8.11
  - rbs760_firmware < 6.3.8.11
  - rs100_firmware < 1.0.1.80
  - rs200_firmware < 1.0.1.90
  - rs280_firmware < 1.0.1.90
  - rs300_firmware < 1.0.1.90
  - rs500_firmware < 1.0.1.90
  - rs600_firmware < 1.0.1.90
  - rs70_firmware < 1.0.1.80
  - rs90_firmware < 1.0.1.80
patched:
  - be9300_firmware 1.0.1.84
  - mr60_firmware 1.1.8.142
  - ms60_firmware 1.1.8.142
  - r6700ax_firmware 1.0.18.164
  - rax10_firmware 1.0.5.50
  - rax120_firmware 1.2.10.56
  - rax120v2_firmware 1.2.10.56
  - rax20_firmware 1.0.17.142
  - rax28_firmware 1.0.14.108
  - rax29_firmware 1.0.14.108
  - rax30_firmware 1.0.14.108
  - rax36s_firmware 1.0.5.50
  - rax43_firmware 1.0.17.142
  - rax45_firmware 1.0.17.142
  - rax50_firmware 1.0.17.142
  - rax70_firmware 1.0.19.172
  - rbr760_firmware 6.3.8.11
  - rbs760_firmware 6.3.8.11
  - rs100_firmware 1.0.1.80
  - rs200_firmware 1.0.1.90
  - rs280_firmware 1.0.1.90
  - rs300_firmware 1.0.1.90
  - rs500_firmware 1.0.1.90
  - rs600_firmware 1.0.1.90
  - rs70_firmware 1.0.1.80
  - rs90_firmware 1.0.1.80
published: '2026-08-11'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T03:00:03.993'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11814'
references:
  - url: 'https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/be9300/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/mr60/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/ms60/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/r6700ax/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax10/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax120/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax120v2/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax20/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax28/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax29/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax30/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax36s/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax43/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax45/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax50/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax70/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rbr760/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rbs760/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs100/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs200/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs280/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs300/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs500/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs600/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs70/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs90/'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
tags:
  - nvd
epss: 0.00914
epssPercentile: 0.58431
ingestedAt: '2026-08-29T19:41:14.560Z'
---

## Overview

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.

## Affected

- `be9300_firmware < 1.0.1.84`
- `mr60_firmware < 1.1.8.142`
- `ms60_firmware < 1.1.8.142`
- `r6700ax_firmware < 1.0.18.164`
- `rax10_firmware < 1.0.5.50`
- `rax120_firmware < 1.2.10.56`
- `rax120v2_firmware < 1.2.10.56`
- `rax20_firmware < 1.0.17.142`
- `rax28_firmware < 1.0.14.108`
- `rax29_firmware < 1.0.14.108`
- `rax30_firmware < 1.0.14.108`
- `rax36s_firmware < 1.0.5.50`
- `rax43_firmware < 1.0.17.142`
- `rax45_firmware < 1.0.17.142`
- `rax50_firmware < 1.0.17.142`
- `rax70_firmware < 1.0.19.172`
- `rbr760_firmware < 6.3.8.11`
- `rbs760_firmware < 6.3.8.11`
- `rs100_firmware < 1.0.1.80`
- `rs200_firmware < 1.0.1.90`
- `rs280_firmware < 1.0.1.90`
- `rs300_firmware < 1.0.1.90`
- `rs500_firmware < 1.0.1.90`
- `rs600_firmware < 1.0.1.90`
- `rs70_firmware < 1.0.1.80`
- `rs90_firmware < 1.0.1.80`

## Remediation

Upgrade past the affected range:

- `be9300_firmware 1.0.1.84`
- `mr60_firmware 1.1.8.142`
- `ms60_firmware 1.1.8.142`
- `r6700ax_firmware 1.0.18.164`
- `rax10_firmware 1.0.5.50`
- `rax120_firmware 1.2.10.56`
- `rax120v2_firmware 1.2.10.56`
- `rax20_firmware 1.0.17.142`
- `rax28_firmware 1.0.14.108`
- `rax29_firmware 1.0.14.108`
- `rax30_firmware 1.0.14.108`
- `rax36s_firmware 1.0.5.50`
- `rax43_firmware 1.0.17.142`
- `rax45_firmware 1.0.17.142`
- `rax50_firmware 1.0.17.142`
- `rax70_firmware 1.0.19.172`
- `rbr760_firmware 6.3.8.11`
- `rbs760_firmware 6.3.8.11`
- `rs100_firmware 1.0.1.80`
- `rs200_firmware 1.0.1.90`
- `rs280_firmware 1.0.1.90`
- `rs300_firmware 1.0.1.90`
- `rs500_firmware 1.0.1.90`
- `rs600_firmware 1.0.1.90`
- `rs70_firmware 1.0.1.80`
- `rs90_firmware 1.0.1.80`
