Description
A
security flaw was discovered in the NETGEAR WAX333 Access Point that could
allow someone already logged in and connected to the local network to make
unauthorized changes to the device's settings
Published: 2026-07-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An input validation flaw in NETGEAR WAX333 Access Points lets an authenticated user who is already logged on to the local network change device settings that they should not be able to alter. The weakness (CWE‑20) can be exploited only by users with valid credentials, leading to unauthorized configuration changes that affect the integrity and availability of the wireless network service.

Affected Systems

NETGEAR WAX333 Insight Managed WiFi 6 AX3000 Dual‑band Access Point with Gigabit PoE (3‑pack) is affected. Firmware versions prior to V12.8.0.100 contain the flaw; newer firmware includes the fix.

Risk and Exploitability

The CVSS score of 4.3 indicates low‑to‑moderate severity, and an EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. An attacker would need local network access and valid device credentials; the attack vector is an authenticated local access scenario.

Generated by OpenCVE AI on July 31, 2026 at 05:54 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionWAX333 Insight Managed WiFi 6 AX3000 Dual-band Access Point with Gigabit PoE (3-pack) V12.8.0.100 https://www.netgear.com/support/product/WAX333/


OpenCVE Recommended Actions

  • Upgrade the firmware to V12.8.0.100 or later.
  • Ensure automatic updates are enabled to receive future patches.
  • Enforce strong password policies or implement multi‑factor authentication for device login to reduce credential misuse.

Generated by OpenCVE AI on July 31, 2026 at 05:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
References

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connected to the local network to make unauthorized changes to the device's settings
Title Authenticated users can make unauthorized changes on NETGEAR WAX333 Access Points
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-07-15T16:04:55.710Z

Reserved: 2026-07-14T16:31:02.509Z

Link: CVE-2026-62659

cve-icon Vulnrichment

Updated: 2026-07-15T14:03:08.267Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses
  • CWE-20

    Improper Input Validation