CVE-2026-62657: Router Cert Validation Bypass in NETGEAR XR1000 / Nighthawk
CVE-2026-62657 Published on July 14, 2026
Certificate validation vulnerability in NETGEAR Gaming Router and certain Nighthawk models
A security flaw in the router's certificate validation process was
discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take
control of the device.
Weakness Type
Missing Validation of OpenSSL Certificate
The software uses OpenSSL and trusts or uses a certificate without using the SSL_get_verify_result() function to ensure that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated.
Products Associated with CVE-2026-62657
Want to know whenever a new CVE is published for Netgear Raxe500? stack.watch will email you.
Affected Versions
NETGEAR MR70:- Before V1.0.4.48 is affected.
- Before V1.0.4.48 is affected.
- Before V1.2.14.114 is affected.
- Before V1.0.2.86 is affected.