4.7

CVE-2026-62658

Post-authentication Command Injection Vulnerability in certain Nighthawk RAX series models

A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers
that could allow someone already logged in to the device to run unauthorized commands
or code on the router.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNETGEAR
Produkt RAX43
Default Statusunaffected
Version 0
Version < V1.0.17.142
Status affected
HerstellerNETGEAR
Produkt RAX45
Default Statusunaffected
Version 0
Version < V1.0.17.142
Status affected
HerstellerNETGEAR
Produkt RAX50
Default Statusunaffected
Version 0
Version < V1.0.17.142
Status affected
HerstellerNETGEAR
Produkt RAX54S
Default Statusunaffected
Version 0
Version < V1.0.17.142
Status affected
HerstellerNETGEAR
Produkt RAX54Sv2
Default Statusunaffected
Version 0
Version < V1.1.6.36
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.092
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NETGEAR 4.7 0 0
CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.netgear.com/support/product/rax43/
https://www.netgear.com/support/product/rax45/
https://www.netgear.com/support/product/rax50/
https://www.netgear.com/support/product/rax54sv2/
https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory