# CVE-2026-62657

## Summary

- **CVE ID:** CVE-2026-62657
- **Severity:** MEDIUM
- **CVSS Score:** 4.9 (CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber)
- **CWE:** CWE-599
- **Published:** Jul 14, 2026
- **Last Modified:** Jul 15, 2026

## Description

A security flaw in the router's certificate validation process was
discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take
control of the device.

## Affected Products

- NETGEAR — RAXE500 (0)
- NETGEAR — XR1000 (0)
- NETGEAR — MR70 (0)
- NETGEAR — MS70 (0)

## References

- [CNA](https://www.netgear.com/support/product/mr70/)
- [CNA](https://www.netgear.com/support/product/raxe500/)
- [CNA](https://www.netgear.com/support/product/ms70/)
- [CNA](https://www.netgear.com/support/product/xr1000/)
- [CNA](https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._