CVE-2026-9211: NETGEAR CAX30 Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.

Affected products

  • NETGEAR CAX30 Firmware: before 2.2.1.4 (fixed in 2.2.1.4)
  • NETGEAR RAX30 Firmware: before 1.0.10.94 (fixed in 1.0.10.94)
  • NETGEAR RAX5 Firmware: before 1.0.5.34 (fixed in 1.0.5.34)
  • NETGEAR RAXE300 Firmware: before 1.0.10.72 (fixed in 1.0.10.72)

Published 2026-06-09. Last modified 2026-07-23.