CVE-2026-9213: NETGEAR MR70 Firmware

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.

Affected products

  • NETGEAR MR70 Firmware: before 1.0.4.48 (fixed in 1.0.4.48)
  • NETGEAR MS70 Firmware: before 1.0.4.48 (fixed in 1.0.4.48)
  • NETGEAR RAXE500 Firmware: before 1.2.14.114 (fixed in 1.2.14.114)
  • NETGEAR XR1000 Firmware: before 1.0.2.86 (fixed in 1.0.2.86)

Published 2026-06-09. Last modified 2026-07-23.