Description

A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.

Severity (CVSS)

Base score5.4
SeverityMedium
VersionCVSS 4.0
VectorCVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Provided byCNA

Weaknesses

  • CWE-20 — CWE-20 Improper input validation

Affected products

VendorProductVersions
NETGEARRAXE4500 to <V1.2.14.114
NETGEARRAXE5000 to <V1.2.14.114

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 15 Jul 2026 07:06 UTC.