CVE-2026-62657: Router Cert Validation Bypass in NETGEAR XR1000 / Nighthawk
CVE-2026-62657 Published on July 14, 2026

Certificate validation vulnerability in NETGEAR Gaming Router and certain Nighthawk models
A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device.

Vendor Advisory NVD

Weakness Type

Missing Validation of OpenSSL Certificate

The software uses OpenSSL and trusts or uses a certificate without using the SSL_get_verify_result() function to ensure that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated.


Products Associated with CVE-2026-62657

Want to know whenever a new CVE is published for Netgear Raxe500? stack.watch will email you.

 

Affected Versions

NETGEAR MR70: NETGEAR MS70: NETGEAR RAXE500: NETGEAR XR1000: