Impact
A security flaw was discovered in Netgear RAX routers that permits a logged‑in user to send specially crafted requests that result in arbitrary command execution. The vulnerability originates from insufficient validation of user input, enabling injection of system commands. An attacker who can successfully exploit this could modify router configuration, disrupt service, or otherwise compromise the device’s security. The flaw requires the attacker to be authenticated to the router, therefore the attack vector is post‑authenticated.
Affected Systems
The flaw affects Netgear Nighthawk RAXE450 and RAXE500 models. Devices running firmware older than version 1.2.14.114 are potentially vulnerable. The affected devices are the Nighthawk AXE10000 Tri‑Band Wi‑Fi 6E Router (RAXE450) and the Nighthawk AX12 12‑Stream AXE11000 Tri‑Band Wi‑Fi 6E Router (RAXE500).
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of <1% suggests the probability of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a valid authenticated session, so an attacker would need access to a user account with administrative privileges or to compromise an existing session. No public exploits are known. Given the moderate CVSS and low EPSS, the overall risk is considered moderate but mitigable through firmware updates.
OpenCVE Enrichment