CVE-2026-11739EPSS p63.7%

CVE-2026-11739CVE-2026-11739

netgear / ms90_firmware

Description

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.

Scoring

CVSS 6.4 ()
VectorCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS1.07% probability of exploitation · percentile 63.7% · 2026-10-06T12:00:23Z
Last modified2026-09-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.