BE9300 vulnerability

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.

Published 11 Aug 2026Updated 9 Sep 202627 sources
CVSS 4.9

What happened

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.

Affected versions

BE9300: before V1.0.1.84 (custom); before V1.1.8.142 (custom); before V1.0.18.164 (custom); before V1.0.5.50 (custom); before V1.2.10.56 (custom); before V1.0.17.142 (custom); before V1.0.14.108 (custom); before V1.0.19.172 (custom); before V6.3.8.11 (custom); before V1.0.1.80 (custom); before V1.0.1.90 (custom) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.