Privilege Escalation via Remote Command Execution in NETGEAR Nighthawk RAX Router
CVE-2026-62658 Published on July 14, 2026

Post-authentication Command Injection Vulnerability in certain Nighthawk RAX series models
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.

Vendor Advisory NVD

Weakness Type

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


Products Associated with CVE-2026-62658

Want to know whenever a new CVE is published for Netgear products? stack.watch will email you.

 
 
 

Affected Versions

NETGEAR RAX43: NETGEAR RAX45: NETGEAR RAX50: NETGEAR RAX54S: NETGEAR RAX54Sv2: