CVE-2026-62657 Details
Description
A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device.
A vulnerability exists in the certificate validation process of the NETGEAR XR1000 Gaming Router, RAXE500 Nighthawk AX12 Router, and the MR70 and MS70 Nighthawk Mesh WiFi 6 Systems. This flaw could enable an unauthorized individual to remotely access and control the affected device.
Users can update to the latest firmware version available for their specific device model. For the XR1000, the latest firmware version is 1.0.2.86. The RAXE500 also has a latest version of 1.2.14.114. For the MR70 and MS70 mesh systems, the latest firmware version is 1.0.4.48.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory | Netgear, Inc. | |
| https://www.netgear.com/support/product/mr70/ | Netgear, Inc. | ProductVendor |
| https://www.netgear.com/support/product/ms70/ | Netgear, Inc. | ProductVendor |
| https://www.netgear.com/support/product/raxe500/ | Netgear, Inc. | ProductVendor |
| https://www.netgear.com/support/product/xr1000/ | Netgear, Inc. | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-599 | Missing Validation of OpenSSL Certificate | Netgear, Inc. |
Affected Products
| Product | Versions |
|---|---|
| NETGEAR XR1000 | < 1.0.2.86 |
CPE
Remediation
| |
| NETGEAR MR70 | All versions |
CPE
Remediation
| |
| NETGEAR MS70 | All versions |
CPE
Remediation
| |
| NETGEAR RAXE500 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | Netgear, Inc. |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | Netgear, Inc. |
Volerion