CVE-2026-62656
MEDIUMPost-authenticated command injection vulnerability found in certain NETGEAR RAX models
Title source: cnaDescription
A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.
References (3)
Core 3
Core References
Patch product
patch
https://www.netgear.com/support/product/raxe450/
Patch product
patch
https://www.netgear.com/support/product/raxe500/
Vendor Advisory vendor-advisory
https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory
Scores
CVSS v4
5.4
EPSS
0.0016
EPSS Percentile
6.0%
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (2)
NETGEAR/RAXE450
< V1.2.14.114
NETGEAR/RAXE500
< V1.2.14.114
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026