CVE-2026-9212
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands
CVSS
8.0
Alto
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 9 jun 2026 · Última mod.: 23 jul 2026 · CWE-20 · CWE-306
0.3%EPSS · 30 días0.3%
2026-08-042026-09-01
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
- kb.netgear.comhttps://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
- www.netgear.comhttps://www.netgear.com/support/product/lbr1020/
- www.netgear.comhttps://www.netgear.com/support/product/lbr20/
- www.netgear.comhttps://www.netgear.com/support/product/r6700ax/
- www.netgear.comhttps://www.netgear.com/support/product/r7800/
- www.netgear.comhttps://www.netgear.com/support/product/r9000/
- www.netgear.comhttps://www.netgear.com/support/product/rax10/
- www.netgear.comhttps://www.netgear.com/support/product/rax120/
- www.netgear.comhttps://www.netgear.com/support/product/rax120v2/
- www.netgear.comhttps://www.netgear.com/support/product/rax36s/
- www.netgear.comhttps://www.netgear.com/support/product/rax70/
- www.netgear.comhttps://www.netgear.com/support/product/rax78/
- www.netgear.comhttps://www.netgear.com/support/product/rbr10/
- www.netgear.comhttps://www.netgear.com/support/product/rbr20/
- www.netgear.comhttps://www.netgear.com/support/product/rbr350/
- www.netgear.comhttps://www.netgear.com/support/product/rbr40/
- www.netgear.comhttps://www.netgear.com/support/product/rbr50/
- www.netgear.comhttps://www.netgear.com/support/product/rbs10/
- www.netgear.comhttps://www.netgear.com/support/product/rbs20/
- www.netgear.comhttps://www.netgear.com/support/product/rbs350/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2024-355858.6 ALT—
——0Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.9hCVE-2026-844857.5 ALT—
——0APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.3hCVE-2026-847008.6 ALT—
——0PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates it; the frame dispatcher (DealMessage) does not require a completed or attempted MetaSync before routing other message types to their handlers. As a result, an unauthenticated remote attacker can connect directly to the replication port and issue TrySync, DBSync, BinlogSync, and RemoveSlaveNode requests, obtaining the full-sync snapshot and live write stream and removing replica nodes, even when requirepass is configured.13hCVE-2026-846968.2 ALT—
——0Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.13hCVE-2026-84357——
——0Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)14hCVE-2026-84325——
——0Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)14h