MR60 vulnerability

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.

Published 11 Aug 2026Updated 9 Sep 202626 sources
CVSS 4.9

What happened

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.

Affected versions

MR60: before V1.1.8.142 (custom); before V1.0.4.48 (custom); before V1.0.2.46 (custom); before V1.0.17.142 (custom); before V1.0.11.148 (custom); before V1.1.6.36 (custom); before V1.2.14.110 (custom); before V1.0.9.6 (custom); before V1.1.0.22 (custom) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.