kb.netgear.comVendor advisory
https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory CVE-2026-62657
MEDIUM
Certificate validation vulnerability in NETGEAR Gaming Router and certain Nighthawk models
Record summary
CVE-2026-62657 has a selected CVSS score of 4.9 (medium).
Description
A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 15, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before V1.0.4.48 | affected |
Default status: unaffected | CVE List | Before V1.0.4.48 | affected |
RAXE500Browse NETGEAR / RAXE500Default status: unaffected | CVE List | Before V1.2.14.114 | affected |
XR1000Browse NETGEAR / XR1000Default status: unaffected | CVE List | Before V1.0.2.86 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-62657 netgear.comproductpatch
https://www.netgear.com/support/product/mr70 netgear.comproductpatch
https://www.netgear.com/support/product/ms70 netgear.comproductpatch
https://www.netgear.com/support/product/raxe500 netgear.comproductpatch
https://www.netgear.com/support/product/xr1000