CVE-2026-11737

EUVD-2026-56189
Insufficient input validation vulnerability in the listed 
NETGEAR models allows authenticated administrators connected to the 
local network to make unauthorized modification to the device software and 
functionality.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.5 MEDIUM
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 11.31%
Affected Products (NVD)
VendorProductVersion
netgearrax20_firmware
𝑥
< 1.0.18.144
netgearrax41_firmware
𝑥
< 1.1.6.36
netgearrax41v2_firmware
𝑥
< 1.1.6.36
netgearrax42_firmware
𝑥
< 1.1.6.36
netgearrax42v2_firmware
𝑥
< 1.1.6.36
netgearrax43_firmware
𝑥
< 1.1.6.36
netgearrax43v2_firmware
𝑥
< 1.1.6.36
netgearrax45_firmware
𝑥
< 1.0.17.142
netgearrax49s_firmware
𝑥
< 1.1.6.36
netgearrax50_firmware
𝑥
< 1.1.6.36
netgearrax50v2_firmware
𝑥
< 1.1.6.36
netgearrax54s_firmware
𝑥
< 1.1.6.36
netgearrax54sv2_firmware
𝑥
< 1.1.6.36
𝑥
= Vulnerable software versions