CVE-2026-62658

MEDIUM

NETGEAR Nighthawk RAX Routers - Authenticated Command Injection

Title source: manual
STIX 2.1

Description

A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.

Scores

CVSS v4 4.7
EPSS 0.0019
EPSS Percentile 9.3%
CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (5)
NETGEAR/RAX43 < V1.0.17.142
NETGEAR/RAX45 < V1.0.17.142
NETGEAR/RAX50 < V1.0.17.142
NETGEAR/RAX54S < V1.0.17.142
NETGEAR/RAX54Sv2 < V1.1.6.36
Published Jul 14, 2026
Tracked Since Jul 14, 2026