Impact
The vulnerability is caused by insufficient input validation in a set of NETGEAR Nighthawk routers, enabling a local administrator with network access to tamper with the device’s firmware and settings. This flaw compromises the integrity of the router and could allow the attacker to install malicious code, alter security controls, or redirect traffic. The weakness is characterized as an input validation error (CWE‑20).
Affected Systems
NETGEAR devices RAX20, RAX41, RAX41v2, RAX42, RAX42v2, RAX43, RAX43v2, RAX45, RAX49S, RAX50, RAX50v2, RAX54S, and RAX54Sv2 are affected. The fix is included in firmware versions RAX20 V1.0.18.144, RAX41/V1.1.6.36, RAX41v2 V1.1.6.36, RAX42 V1.1.6.36, RAX42v2 V1.1.6.36, RAX43 V1.1.6.36, RAX43v2 V1.1.6.36, RAX45 V1.0.17.142, RAX49S V1.1.6.36, RAX50 V1.1.6.36, RAX50v2 V1.1.6.36, RAX54S V1.1.6.36, and RAX54Sv2 V1.1.6.36. Devices marked End‑of‑Support cannot receive updates and should be retired.
Risk and Exploitability
The CVSS base score is 4.3, indicating a moderate impact. No EPSS score is provided, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits. The attack vector requires authenticated access on the local network, typically via the router’s administrative interface. An attacker who gains administrator privileges could modify firmware or configuration, but would need to bypass normal authentication mechanisms. Because the flaw is limited to admins, the risk is moderate and mainly depends on who has administrative rights.
OpenCVE Enrichment