CVE•Published 2026-06-09•Modified 2026-07-23•1 article on news•5 live references•NVD data
CVE-2026-9213Netgear · Mr70_firmware
Vulnerability data via NVD (ingested)
CVSS v3.1
8.1
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
32
Exploit Prediction Scoring System · top 68% of all CVEs
Weaknesses (CWE)
Description
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
Timeline
Published 2026-06-09
Modified 2026-07-23
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-9213Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · OS
os:"Mr70 Firmware"Hosts Shodan identified as running Mr70 Firmware.
More intel sources (5)
Shodan report
vuln:CVE-2026-9213Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-9213Censys host search filtered to this CVE id.
grep.app
CVE-2026-9213Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-9213GitHub code search for direct mentions.
Google dork
"CVE-2026-9213" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (4)
CVE-2026-92134 repos
xairy/linux-kernel-exploitationunknown
A collection of links related to Linux kernel security and exploitation
bsauce/kernel-exploit-factoryC
Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore.
bsauce/kernel-security-learningC
Anything about kernel security. CTF kernel pwn, kernel exploit, kernel fuzz and kernel defense paper, kernel debugging technique, kernel CVE debug.
jaschadub/compromised-packages-checkPython
Scan a repository for known-malicious npm, cratres, and PyPI package versions from recent supply-chain compromises (Mini Shai-Hulud, TanStack, @cap-js/mbt, etc). UPDATED 6 TIMES A …