Some NETGEAR Nighthawk devices allow administrators to tamper with the device
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
Insufficient input validation vulnerability in the listed
NETGEAR models allows authenticated administrators connected to the
local network to make unauthorized modification to the device software and
functionality.
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber
Affected products
NETGEAR · RAX20NETGEAR · RAX41NETGEAR · RAX41v2NETGEAR · RAX42NETGEAR · RAX42v2NETGEAR · RAX43NETGEAR · RAX43v2NETGEAR · RAX45NETGEAR · RAX49SNETGEAR · RAX50NETGEAR · RAX50v2NETGEAR · RAX54SNETGEAR · RAX54Sv2References
https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/rax20/https://www.netgear.com/support/product/rax41/https://www.netgear.com/support/product/rax41v2/https://www.netgear.com/support/product/rax42/https://www.netgear.com/support/product/rax42v2/https://www.netgear.com/support/product/rax43/https://www.netgear.com/support/product/rax43v2/https://www.netgear.com/support/product/rax45/https://www.netgear.com/support/product/rax49s/https://www.netgear.com/support/product/rax50/https://www.netgear.com/support/product/rax50v2/