CVE-2026-11734
Awaiting Analysis Awaiting Analysis - Queue

Authenticated Admin Buffer Overflow in NETGEAR Devices Causes Denial of Service

Vulnerability report for CVE-2026-11734, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-09-09

Assigner: Netgear, Inc.

Description

A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-09-09
Generated
2026-09-22
AI Q&A
2026-08-11
EPSS Evaluated
2026-09-20
NVD
EUVD

Affected Vendors & Products

Showing 15 associated CPEs
Vendor Product Version / Range
netgear mr70_firmware to 1.0.4.48 (exc)
netgear mr90_firmware to 1.0.2.46 (exc)
netgear ms70_firmware to 1.0.4.48 (inc)
netgear ms90_firmware to 1.0.2.46 (exc)
netgear rax41_firmware to 1.1.6.36 (exc)
netgear rax41v2_firmware to 1.1.6.36 (exc)
netgear rax42_firmware to 1.1.6.36 (exc)
netgear rax42v2_firmware to 1.1.6.36 (exc)
netgear rax43_firmware to 1.1.6.36 (exc)
netgear rax43v2_firmware to 1.1.6.36 (exc)
netgear rax49s_firmware to 1.1.6.36 (exc)
netgear rax50_firmware to 1.1.6.36 (exc)
netgear rax50v2_firmware to 1.1.6.36 (exc)
netgear rax54s_firmware to 1.1.6.36 (exc)
netgear rax54sv2_firmware to 1.1.6.36 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a buffer overflow vulnerability in certain NETGEAR models. It allows an authenticated admin user to cause the device to temporarily stop functioning.

Detection Guidance

Detection requires checking for affected NETGEAR models and monitoring for temporary unavailability. No specific commands are provided in the context. Review device logs for admin login anomalies or unexpected crashes.

Impact Analysis

An attacker with admin access could exploit this to make the device unavailable, disrupting network services temporarily.

Compliance Impact

The vulnerability allows an authenticated admin user to cause temporary unavailability of the device through a buffer overflow. This could disrupt network operations and potentially lead to data processing interruptions, which may impact compliance with standards requiring continuous availability of systems handling sensitive data.

Mitigation Strategies

Immediate mitigation includes restricting admin access to trusted users only and monitoring device performance for crashes. Apply any available firmware updates from NETGEAR if released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11734. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart