Unauth Cmd Exec via Crafted Requests on NETGEAR RAX Routers
CVE-2026-62656 Published on July 14, 2026

Post-authenticated command injection vulnerability found in certain NETGEAR RAX models
A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.

Vendor Advisory NVD

Weakness Type

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


Products Associated with CVE-2026-62656

stack.watch emails you whenever new vulnerabilities are published in Netgear Raxe450 or Netgear Raxe500. Just hit a watch button to start following.

 
 

Affected Versions

NETGEAR RAXE450: NETGEAR RAXE500: