CVE-2026-62659: Authenticated users can make unauthorized changes on NETGEAR WAX333 Access Points
A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connected to the local network to make unauthorized changes to the device's settings
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR WAX333 Insight Managed WiFi 6 AX3000 Dual-band Access Point with Gigabit PoE (3-pack)to a version that resolves this vulnerability.Fixed in V12.8.0.100 - Compensating control
Restrict administrative access to the NETGEAR WAX333 to prevent authenticated local-network users from making unauthorized changes until the firmware is updated to V12.8.0.100.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62659?
The severity of CVE-2026-62659 is medium with a CVSS score of 4.3.
How do I fix CVE-2026-62659?
To fix CVE-2026-62659, ensure that your NETGEAR WAX333 Access Point firmware is updated to the latest version available from NETGEAR.
What are the potential impacts of CVE-2026-62659?
CVE-2026-62659 may allow authenticated users to make unauthorized changes to the settings of the NETGEAR WAX333 Access Point.
Who is affected by CVE-2026-62659?
Anyone using the NETGEAR WAX333 Access Point with authenticated access could be affected by CVE-2026-62659.
When was CVE-2026-62659 published?
CVE-2026-62659 was published on July 14, 2026.