CVE-2026-62657
A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.9
- CVSS vector
- CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
- EPSS probability
- 0.15%
- CWE
- CWE-599
- Published
- 2026-07-14
- Last modified
- 2026-07-15
Affected products
- NETGEAR RAXE500
- NETGEAR XR1000
- NETGEAR MR70
- NETGEAR MS70
Weakness type
Related vulnerabilities
- CVE-2026-25060 — OpenList Insecure TLS Default Configuration
- CVE-2025-12553 — Server Certificate Verification Disabled
- CVE-2022-31105 — Argo CD's certificate verification is skipped for connections to OIDC providers
- CVE-2021-21374 — Nimble fails to validate certificates due to insecure httpClient defaults