4.7
CVE-2026-62658
- EPSS 0.19%
- Veröffentlicht 14.07.2026 17:46:12
- Zuletzt bearbeitet 15.07.2026 18:20:21
- CVE-Watchlists
- Unerledigt
Post-authentication Command Injection Vulnerability in certain Nighthawk RAX series models
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNETGEAR
≫
Produkt
RAX43
Default Statusunaffected
Version
0
Version <
V1.0.17.142
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX45
Default Statusunaffected
Version
0
Version <
V1.0.17.142
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX50
Default Statusunaffected
Version
0
Version <
V1.0.17.142
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX54S
Default Statusunaffected
Version
0
Version <
V1.0.17.142
Status
affected
HerstellerNETGEAR
≫
Produkt
RAX54Sv2
Default Statusunaffected
Version
0
Version <
V1.1.6.36
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.092 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NETGEAR | 4.7 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://www.netgear.com/support/product/rax43/
https://www.netgear.com/support/product/rax45/
https://www.netgear.com/support/product/rax50/
https://www.netgear.com/support/product/rax54sv2/
https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory