---
id: CVE-2026-9216
title: >-
  An insufficient input validation vulnerability in the listed NETGEAR RAX
  series models allows a network-adjacent attacker having network access (such
  as WiFi credentials) to crash the router's management UI
summary: >-
  An insufficient input validation vulnerability in the listed NETGEAR RAX
  series models allows a network-adjacent attacker having network access (such
  as WiFi credentials) to crash the router's management UI. There is no
  confidentiality o…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-121
vendor: netgear
product: rax30_firmware
affected:
  - rax30_firmware < 1.0.9.92
  - rax35_firmware < 1.0.10.72
  - rax38_firmware < 1.0.6.106
  - rax40_firmware < 1.0.6.106
  - raxe300_firmware < 1.0.10.72
patched:
  - rax30_firmware 1.0.9.92
  - rax35_firmware 1.0.10.72
  - rax38_firmware 1.0.6.106
  - rax40_firmware 1.0.6.106
  - raxe300_firmware 1.0.10.72
published: '2026-09-08'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T21:20:31.633'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9216'
references:
  - url: 'https://kb.netgear.com/000070912/September-2026-NETGEAR-Security-Advisory'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax30'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax35'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax38'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax40'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/raxe300'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
tags:
  - nvd
  - cve.org
epss: 0.0023
epssPercentile: 0.14046
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T18:26:42.700722Z'
ingestedAt: '2026-09-08T19:08:49.634Z'
---

## Overview

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.

## Affected

- `rax30_firmware < 1.0.9.92`
- `rax35_firmware < 1.0.10.72`
- `rax38_firmware < 1.0.6.106`
- `rax40_firmware < 1.0.6.106`
- `raxe300_firmware < 1.0.10.72`

## Remediation

Upgrade past the affected range:

- `rax30_firmware 1.0.9.92`
- `rax35_firmware 1.0.10.72`
- `rax38_firmware 1.0.6.106`
- `rax40_firmware 1.0.6.106`
- `raxe300_firmware 1.0.10.72`
