Impact
A post‑authentication command injection flaw allows an authenticated user to execute arbitrary commands on the routerCWE‑20) that can be abused to run unintended code or system commands; the description indicates it may give the attacker control over the device and its network traffic. As the flaw requires prior login, it does not expose the router to unauthenticated attackers, but users who have gained legitimate or compromised credentials can exploit it.
Affected Systems
Affected devices include the NETGEAR Nighthawk RAX series: RAX43 (EoS) with firmware Nighthawk AX5 V1.0.17.142, RAX45 (EoS) with Nighthawk AX6 V1.0.17.142, RAX50 with Nighthawk AX6 V1.0.17.142, RAX54S with Nighthawk AX6 V1.0.17.142, and AX6 V1.1.6.36. Devices marked (EoS) have reached End‑of‑Support and will not receive further updates.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate impact, and the EPSS score of <1% suggests exploiting this vulnerability is currently unlikely to be widely automated. The flaw is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Likely attack progression requires an attacker to already be logged into the router via the web interface or API, after which the flaw can be leveraged to inject and execute system commands.
OpenCVE Enrichment