4.9
CVE-2026-62657
- EPSS 0.11%
- Veröffentlicht 14.07.2026 17:46:13
- Zuletzt bearbeitet 15.07.2026 18:20:21
- CVE-Watchlists
- Unerledigt
Certificate validation vulnerability in NETGEAR Gaming Router and certain Nighthawk models
A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNETGEAR
≫
Produkt
MR70
Default Statusunaffected
Version
0
Version <
V1.0.4.48
Status
affected
HerstellerNETGEAR
≫
Produkt
MS70
Default Statusunaffected
Version
0
Version <
V1.0.4.48
Status
affected
HerstellerNETGEAR
≫
Produkt
RAXE500
Default Statusunaffected
Version
0
Version <
V1.2.14.114
Status
affected
HerstellerNETGEAR
≫
Produkt
XR1000
Default Statusunaffected
Version
0
Version <
V1.0.2.86
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.013 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NETGEAR | 4.9 | 0 | 0 |
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
|
CWE-599 Missing Validation of OpenSSL Certificate
The product uses OpenSSL and trusts or uses a certificate without using the SSL_get_verify_result() function to ensure that the certificate satisfies all necessary security requirements.
https://www.netgear.com/support/product/xr1000/
https://www.netgear.com/support/product/raxe500/
https://www.netgear.com/support/product/mr70/
https://www.netgear.com/support/product/ms70/
https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory