Junglewise Threat Intelligence

CVE-2026-62657: NETGEAR Nighthawk and Gaming Routers certificate validation bypass

CVE-2026-62657 · Severity: info · CVSS 4.9 · Published 2026-07-14

Executive brief

A security flaw in the certificate validation process of several NETGEAR Nighthawk and gaming routers could allow an unauthorized person to gain remote access to the device. These routers are used to manage home and small office network traffic and security. If exploited, an attacker could take full control of the router, potentially monitoring network traffic or modifying device settings.

Technical details

A vulnerability classified as CWE-599 (Missing Validation of OpenSSL Certificate) exists in the certificate validation logic of multiple NETGEAR router models, including the XR1000 and RAXE500. The flaw allows an attacker to bypass security checks during the SSL/TLS handshake process. According to the CVSS 4.0 vector, the attack requires an adjacent network position and high complexity, likely involving a man-in-the-middle (MitM) scenario. Successful exploitation can lead to unauthorized remote access and full administrative control over the device. Patches have been released for affected models, including versions V1.0.4.48 for MR70/MS70, V1.2.14.114 for RAXE500, and V1.0.2.86 for XR1000.

Affected products

  • NETGEAR MR70 < V1.0.4.48
  • NETGEAR MS70 < V1.0.4.48
  • NETGEAR RAXE500 < V1.2.14.114
  • NETGEAR XR1000 Gaming Router < V1.0.2.86

Timeline

  • 2026-07-14: disclosed: Initial publication of CVE-2026-62657
  • 2026-07-14: advisory

References

Related threats