Description
A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.
Severity (CVSS)
| Base score | 5.4 |
|---|---|
| Severity | Medium |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P |
| Provided by | CNA |
Weaknesses
- CWE-20 — CWE-20 Improper input validation
Affected products
| Vendor | Product | Versions |
|---|---|---|
| NETGEAR | RAXE450 | 0 to <V1.2.14.114 |
| NETGEAR | RAXE500 | 0 to <V1.2.14.114 |
References
- https://www.netgear.com/support/product/raxe450/ (product patch)
- https://www.netgear.com/support/product/raxe500/ (product patch)
Generated from the official CVE List on 15 Jul 2026 07:06 UTC.