CVE-2026-62656

MEDIUM

Post-authenticated command injection vulnerability found in certain NETGEAR RAX models

Title source: cna
STIX 2.1

Description

A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.

References (3)

Core 3

Scores

CVSS v4 5.4
EPSS 0.0016
EPSS Percentile 6.0%
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
NETGEAR/RAXE450 < V1.2.14.114
NETGEAR/RAXE500 < V1.2.14.114
Published Jul 14, 2026
Tracked Since Jul 14, 2026