CVE-2026-11814
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify l
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-295
Not enough EPSS history yet.
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
- www.netgear.comhttps://www.netgear.com/support/product/be9300/
- www.netgear.comhttps://www.netgear.com/support/product/mr60/
- www.netgear.comhttps://www.netgear.com/support/product/ms60/
- www.netgear.comhttps://www.netgear.com/support/product/r6700ax/
- www.netgear.comhttps://www.netgear.com/support/product/rax10/
- www.netgear.comhttps://www.netgear.com/support/product/rax120/
- www.netgear.comhttps://www.netgear.com/support/product/rax120v2/
- www.netgear.comhttps://www.netgear.com/support/product/rax20/
- www.netgear.comhttps://www.netgear.com/support/product/rax28/
- www.netgear.comhttps://www.netgear.com/support/product/rax29/
- www.netgear.comhttps://www.netgear.com/support/product/rax30/
- www.netgear.comhttps://www.netgear.com/support/product/rax36s/
- www.netgear.comhttps://www.netgear.com/support/product/rax43/
- www.netgear.comhttps://www.netgear.com/support/product/rax45/
- www.netgear.comhttps://www.netgear.com/support/product/rax50/
- www.netgear.comhttps://www.netgear.com/support/product/rax70/
- www.netgear.comhttps://www.netgear.com/support/product/rbr760/
- www.netgear.comhttps://www.netgear.com/support/product/rbs760/
- www.netgear.comhttps://www.netgear.com/support/product/rs100/
- www.netgear.comhttps://www.netgear.com/support/product/rs200/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-484375.5 MED—
———CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.6hCVE-2026-181298.1 HIG—
———Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.8hCVE-2026-155547.4 HIG—
——0the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.9hCVE-2026-667606.4 MED—
——0SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability.8hCVE-2026-664104.8 MED6.1%
——2Android and iOS apps ECOVACS PRO App improperly validate server certificates.
Communication may be retrieved and/or altered.1dCVE-2026-664064.8 MED4.8%
——1DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.
A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.1d