CVE-2026-62659
MEDIUMAuthenticated users can make unauthorized changes on NETGEAR WAX333 Access Points
Title source: cnaDescription
A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connected to the local network to make unauthorized changes to the device's settings
References (2)
Core 2
Core References
Patch patch
product
https://www.netgear.com/support/product/wax333
Vendor Advisory vendor-advisory
https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory
Scores
CVSS v4
4.3
EPSS
0.0019
EPSS Percentile
9.5%
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (2)
NETGEAR/WAX333
< V12.8.0.100
NETGEAR/WAX333
< V2.8.0.100
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026