CVE-2026-9216: NETGEAR RAX30 Firmware

Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.

Affected products

  • NETGEAR RAX30 Firmware: before 1.0.9.92 (fixed in 1.0.9.92)
  • NETGEAR RAX35 Firmware: before 1.0.10.72 (fixed in 1.0.10.72)
  • NETGEAR RAX38 Firmware: before 1.0.6.106 (fixed in 1.0.6.106)
  • NETGEAR RAX40 Firmware: before 1.0.6.106 (fixed in 1.0.6.106)
  • NETGEAR RAXE300 Firmware: before 1.0.10.72 (fixed in 1.0.10.72)

Published 2026-09-08. Last modified 2026-09-11.