CVE-2026-62658
MEDIUMNETGEAR Nighthawk RAX Routers - Authenticated Command Injection
Title source: manualDescription
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.
References (5)
Core 5
Core References
Patch product
patch
https://www.netgear.com/support/product/rax43/
Patch product
patch
https://www.netgear.com/support/product/rax45/
Patch product
patch
https://www.netgear.com/support/product/rax50/
Patch product
patch
https://www.netgear.com/support/product/rax54sv2/
Vendor Advisory vendor-advisory
https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory
Scores
CVSS v4
4.7
EPSS
0.0019
EPSS Percentile
9.3%
CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (5)
NETGEAR/RAX43
< V1.0.17.142
NETGEAR/RAX45
< V1.0.17.142
NETGEAR/RAX50
< V1.0.17.142
NETGEAR/RAX54S
< V1.0.17.142
NETGEAR/RAX54Sv2
< V1.1.6.36
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026