Impact
The vulnerability is an insufficient input validation flaw that allows an authenticated administrator who is connected to the local network to make unauthorized changes to the router’s software and functionality. An attacker who obtains administrative credentials can thus alter configuration settings or the firmware behaviour without permission, potentially compromising the device’s intended operation, bypassing security controls, or enabling further attacks within the local network.
Affected Systems
Affected brands include NETGEAR’s Nighthawk R7000, RAXE500, and RS700 routers. The R7000 model is End‑of‑Support and will not receive updates; the RAXE500 requires firmware V1.2.14.114 or newer, and the RS700 requires firmware V1.0.7.66 or newer. All devices should be updated to these or later versions if available.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV. Attack requires local network access and valid administrative credentials; therefore it is most likely exploited by insiders or compromised internal hosts. Once authenticated, the attacker can modify device configuration or firmware without detection, effectively degrading the router’s security or functionality.
OpenCVE Enrichment