A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory | Vendor Advisory |
| https://www.netgear.com/support/product/mr70/ | Product |
| https://www.netgear.com/support/product/ms70/ | Product |
| https://www.netgear.com/support/product/raxe500/ | Product |
| https://www.netgear.com/support/product/xr1000/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
23 Jul 2026, 08:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
18 Jun 2026, 14:57
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
| First Time |
Netgear raxe500
Netgear raxe500 Firmware Netgear ms70 Firmware Netgear ms70 Netgear xr1000 Firmware Netgear mr70 Firmware Netgear mr70 Netgear xr1000 Netgear |
|
| CPE | cpe:2.3:h:netgear:raxe500:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:mr70:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:raxe500_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:ms70_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:xr1000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ms70:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:mr70_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:xr1000:-:*:*:*:*:*:*:* |
|
| References | () https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory - Vendor Advisory | |
| References | () https://www.netgear.com/support/product/mr70/ - Product | |
| References | () https://www.netgear.com/support/product/ms70/ - Product | |
| References | () https://www.netgear.com/support/product/raxe500/ - Product | |
| References | () https://www.netgear.com/support/product/xr1000/ - Product |
11 Jun 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device. |
10 Jun 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 17:17
Updated : 2026-07-23 08:10
NVD link : CVE-2026-9213
Mitre link : CVE-2026-9213
CVE.ORG link : CVE-2026-9213
JSON object : View
Products Affected
netgear
- ms70_firmware
- xr1000
- mr70_firmware
- xr1000_firmware
- mr70
- ms70
- raxe500
- raxe500_firmware
CWE
CWE-20
Improper Input Validation
