CVE-2026-62658: Post-authentication Command Injection Vulnerability in certain Nighthawk RAX series models
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR Nighthawk RAX43to a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR Nighthawk AX5 5-Stream AX4200 WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR Nighthawk RAX45to a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR Nighthawk AX6 6-Stream AX4300 WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR Nighthawk RAX50to a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR Nighthawk AX6 6-Stream AX5400 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR Nighthawk RAX54Sto a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR Nighthawk AX6 6-Stream AX5400 WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.17.142 - Upgrade
Upgrade
NETGEAR Nighthawk RAX54Sv2to a version that resolves this vulnerability.Fixed in V1.1.6.36 - Compensating control
For models marked (EoS) (RAX43 and RAX45), retire these devices and upgrade to a newer NETGEAR device for continued security support (no security updates are planned).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62658?
CVE-2026-62658 has a medium severity score of 4.7 according to CVSS.
What does CVE-2026-62658 affect?
CVE-2026-62658 affects certain NETGEAR Nighthawk RAX series routers.
How do I fix CVE-2026-62658?
To fix CVE-2026-62658, ensure that your NETGEAR Nighthawk RAX series router firmware is updated to the latest version.
What type of vulnerability is CVE-2026-62658?
CVE-2026-62658 is classified as a post-authentication command injection vulnerability.
Who can exploit CVE-2026-62658?
CVE-2026-62658 can be exploited by anyone who is already logged into the affected NETGEAR Nighthawk RAX series router.