Executive brief
A security vulnerability in certain Netgear Nighthawk routers allows an administrator already logged into the local network to bypass intended management restrictions. This could allow an authorized user to modify router settings or functionality in ways the manufacturer did not intend. While this requires existing administrative access, it represents a failure of the device's internal security controls.
Technical details
The vulnerability is classified as improper input validation (CWE-20) within the management interface of Netgear RAXE450 and RAXE500 routers. An attacker with high privileges (authenticated administrator) and adjacent network access can exploit this flaw to bypass standard functional restrictions. This allows for unauthorized modification of router configuration or behavior that should be restricted even for administrative users. The vulnerability is tracked under CVE-2026-0416 and was reported by Netgear.
Affected products
- Netgear RAXE450
- Netgear RAXE500
Timeline
- 2026-06-09: disclosed: Initial disclosure by Netgear and NVD publication.