CVE-2026-62656: Post-authenticated command injection vulnerability found in certain NETGEAR RAX models
A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR RAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.2.14.114 - Upgrade
Upgrade
NETGEAR RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.2.14.114
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62656?
CVE-2026-62656 has a medium severity rating of 5.4 according to the CVSS scoring system.
How do I fix CVE-2026-62656?
To fix CVE-2026-62656, update the firmware of your NETGEAR RAX router to the latest version provided by the manufacturer.
What impact could CVE-2026-62656 have on my NETGEAR RAX router?
CVE-2026-62656 could allow an authenticated user to execute unauthorized commands on the router, potentially compromising its security and functionality.
Which NETGEAR devices are affected by CVE-2026-62656?
CVE-2026-62656 affects certain models of NETGEAR RAX series routers.
Is CVE-2026-62656 a remote or local vulnerability?
CVE-2026-62656 is considered a post-authenticated local vulnerability, as it requires the attacker to be a logged-in user already.