Privilege Escalation via Remote Command Execution in NETGEAR Nighthawk RAX Router
CVE-2026-62658 Published on July 14, 2026
Post-authentication Command Injection Vulnerability in certain Nighthawk RAX series models
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers
that could allow someone already logged in to the device to run unauthorized commands
or code on the router.
Weakness Type
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Products Associated with CVE-2026-62658
Want to know whenever a new CVE is published for Netgear products? stack.watch will email you.
Affected Versions
NETGEAR RAX43:- Before V1.0.17.142 is affected.
- Before V1.0.17.142 is affected.
- Before V1.0.17.142 is affected.
- Before V1.0.17.142 is affected.
- Before V1.1.6.36 is affected.