Impact
A command injection vulnerability (CWE‑78) exists in certain NETGEAR Nighthawk routers, allowing a network‑adjacent attacker to execute arbitrary commands on the affected devices. The exploitation requires the attacker to intercept and modify local network traffic, compromising the confidential data stored on the router or altering its configuration, leading to a loss of integrity. The CVSS score of 4.9 indicates a moderate risk, but the potential impact could be significant if the device is used for further network attacks.
Affected Systems
Affected products include the NETGEAR Nighthawk line such as the MR60 Mesh WiFi 6 Router, MR70 Mesh WiFi 6 Router, MR90 Tri‑band Mesh WiFi 6E Router, the MS60 and MS70 Mesh WiFi 6 add‑on satellites, MS90 Tri‑band Mesh WiFi 6E add‑on satellite, the RAX20 4‑Stream AX1800 WiFi 6 Router, RAX200 Tri‑band AX12 12‑Stream WiFi Router, RAX35 and RAX35v2 AX4 4‑Stream WiFi 6/AX3000 routers, RAX41, RAX41v2, RAX42, RAX42v2, RAX43, RAX43v2 all AX5 5‑Stream routers, the RAX45 AX6 6‑Stream AX4300 router, RAX49S AX6 6‑Stream AX5300 router, RAX50 and RAX50v2 AX6 6‑Stream AX5400 routers, RAX54S and RAX54Sv2 AX6 6‑Stream AX5400 routers, RAX80 AX8 8‑Stream router, RAXE500 AX12 12‑Stream AXE11000 Tri‑band router, the RS700 BE19000 WiFi 7 Tri‑band router, and the XR1000 XR1000v2 WiFi 6 Pro Gaming routers. Many of these models are marked End‑of‑Support with no further updates planned, and the fixed versions are listed from V1.0.11.148 to V1.2.14.110 as noted in the vendor advisory.
Risk and Exploitability
Because the vulnerability requires active packet sniffing and modification on the local network, the attack surface is limited to network‑adjacent actors, such as compromised local clients or devices that can facilitate a man‑in‑the‑middle attack. The CVSS score of 4.9 and EPSS score of 1% suggest the exploitation likelihood is moderate to low; the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Nevertheless, once compromised, the attacker can alter router configurations or capture sensitive traffic, potentially enabling further network compromise.
OpenCVE Enrichment