No advisories yet.
Solution
Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionRAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Router V1.2.14.114 https://www.netgear.com/support/product/raxe450/ RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router V1.2.14.114 https://www.netgear.com/support/product/raxe500/
Workaround
No workaround given by the vendor.
Thu, 11 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authenticated administrators connected to the local network can modify router functionality beyond what is intended through the standard management interface. | An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality. |
| Title | RAXE450 and RAXE500 routers allow administrators to modify router functionality beyond intended limits | Improper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionality |
Wed, 10 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear
Netgear raxe450 Netgear raxe500 |
|
| Vendors & Products |
Netgear
Netgear raxe450 Netgear raxe500 |
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authenticated administrators connected to the local network can modify router functionality beyond what is intended through the standard management interface. | |
| Title | RAXE450 and RAXE500 routers allow administrators to modify router functionality beyond intended limits | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NETGEAR
Published:
Updated: 2026-06-11T06:02:54.919Z
Reserved: 2025-12-03T04:16:23.205Z
Link: CVE-2026-0416
Updated: 2026-06-09T17:35:12.623Z
Status : Awaiting Analysis
Published: 2026-06-09T17:16:59.313
Modified: 2026-06-11T07:16:26.447
Link: CVE-2026-0416
No data.
OpenCVE Enrichment
Updated: 2026-06-11T07:30:08Z