Description
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers
that could allow someone already logged in to the device to run unauthorized commands
or code on the router.
Published: 2026-07-14
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A post‑authentication command injection flaw allows an authenticated user to execute arbitrary commands on the routerCWE‑20) that can be abused to run unintended code or system commands; the description indicates it may give the attacker control over the device and its network traffic. As the flaw requires prior login, it does not expose the router to unauthenticated attackers, but users who have gained legitimate or compromised credentials can exploit it.

Affected Systems

Affected devices include the NETGEAR Nighthawk RAX series: RAX43 (EoS) with firmware Nighthawk AX5 V1.0.17.142, RAX45 (EoS) with Nighthawk AX6 V1.0.17.142, RAX50 with Nighthawk AX6 V1.0.17.142, RAX54S with Nighthawk AX6 V1.0.17.142, and AX6 V1.1.6.36. Devices marked (EoS) have reached End‑of‑Support and will not receive further updates.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate impact, and the EPSS score of <1% suggests exploiting this vulnerability is currently unlikely to be widely automated. The flaw is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Likely attack progression requires an attacker to already be logged into the router via the web interface or API, after which the flaw can be leveraged to inject and execute system commands.

Generated by OpenCVE AI on July 31, 2026 at 05:57 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionRAX43 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router V1.0.17.142 https://www.netgear.com/support/product/rax43/ RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router V1.0.17.142 https://www.netgear.com/support/product/rax45/ RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router V1.0.17.142 https://www.netgear.com/support/product/rax50/ RAX54S Nighthawk AX6 6-Stream AX5400 WiFi Router V1.0.17.142 https://www.netgear.com/support/product/rax54s/ RAX54Sv2 Nighthawk AX6 6-Stream AX5400 WiFi Router V1.1.6.36 https://www.netgear.com/support/product/rax54sv2/ Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


OpenCVE Recommended Actions

  • Update each router to the latest firmware provided by NETGEAR (for RAX43, RAX45, RAX, and RAX54S use firmware V1.0.17.142; for RAX54Sv2 use firmware V1.1.6.36).
  • If your device is End‑of‑Support, retire it and replace it with a newer NETGEAR model that continues to receive security updates.
  • Enable automatic firmware updates on the router to ensure future patches are applied promptly.

Generated by OpenCVE AI on July 31, 2026 at 05:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
References

Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.
Title Post-authentication Command Injection Vulnerability in certain Nighthawk RAX series models
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 4.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-07-15T17:01:41.135Z

Reserved: 2026-07-14T16:31:02.509Z

Link: CVE-2026-62658

cve-icon Vulnrichment

Updated: 2026-07-15T14:48:40.966Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses
  • CWE-20

    Improper Input Validation