Description
A
security flaw was found in certain NETGEAR RAX models that could allow
a logged-in user to send specially crafted requests to the router and run
unauthorized commands. This could enable the user to make unauthorized changes
to the router and affect its security and operation.
Published: 2026-07-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A security flaw was discovered in Netgear RAX routers that permits a logged‑in user to send specially crafted requests that result in arbitrary command execution. The vulnerability originates from insufficient validation of user input, enabling injection of system commands. An attacker who can successfully exploit this could modify router configuration, disrupt service, or otherwise compromise the device’s security. The flaw requires the attacker to be authenticated to the router, therefore the attack vector is post‑authenticated.

Affected Systems

The flaw affects Netgear Nighthawk RAXE450 and RAXE500 models. Devices running firmware older than version 1.2.14.114 are potentially vulnerable. The affected devices are the Nighthawk AXE10000 Tri‑Band Wi‑Fi 6E Router (RAXE450) and the Nighthawk AX12 12‑Stream AXE11000 Tri‑Band Wi‑Fi 6E Router (RAXE500).

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score of <1% suggests the probability of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a valid authenticated session, so an attacker would need access to a user account with administrative privileges or to compromise an existing session. No public exploits are known. Given the moderate CVSS and low EPSS, the overall risk is considered moderate but mitigable through firmware updates.

Generated by OpenCVE AI on July 31, 2026 at 05:56 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionRAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Router V1.2.14.114 https://www.netgear.com/support/product/raxe450/ RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.114 https://www.netgear.com/support/product/raxe500/


OpenCVE Recommended Actions

  • Download and install firmware V1.2.14.114 from the NETGEAR support site for the affected RAXE450 or RAXE500.
  • Enable automatic firmware updates on the router to receive future security patches in a timely manner.
  • Restrict local access to the router’s administrative interface and disable remote management if it is not required.

Generated by OpenCVE AI on July 31, 2026 at 05:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear raxe450
Netgear raxe500
Vendors & Products Netgear
Netgear raxe450
Netgear raxe500

Wed, 15 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
References

Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.
Title Post-authenticated command injection vulnerability found in certain NETGEAR RAX models
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-07-15T16:53:59.077Z

Reserved: 2026-07-14T16:31:02.508Z

Link: CVE-2026-62656

cve-icon Vulnrichment

Updated: 2026-07-15T14:45:01.603Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses
  • CWE-20

    Improper Input Validation