Improper input validation in NETGEAR Nighthawk router R7000P
Summary
| CVE | CVE-2025-12945 |
|---|---|
| State | PUBLISHED |
| Assigner | NETGEAR |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-09 17:15:48 UTC |
| Updated | 2026-08-26 17:16:46 UTC |
| Description | An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modifications to the router software and functionality impacting its integrity. There is no additional impact to confidentiality or availability. This issue affects R7000P: through 1.3.3.154. |
Risk And Classification
Primary CVSS: v4.0 1.1 LOW from a2826606-91e7-4eb6-899e-8484bd4575d5
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber
Problem Types: CWE-20 | NVD-CWE-noinfo | CWE-20 CWE-20 Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | a2826606-91e7-4eb6-899e-8484bd4575d5 | Secondary | 1.1 | LOW | CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/C... |
| 4.0 | CNA | CVSS | 1.1 | LOW | CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/A... |
| 3.1 | [email protected] | Primary | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | a2826606-91e7-4eb6-899e-8484bd4575d5 | Secondary | 2.4 | LOW | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 2.4 | LOW | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | R7000p | - | All | All | All |
| Operating System | Netgear | R7000p Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.netgear.com/support/product/r7000p | a2826606-91e7-4eb6-899e-8484bd4575d5 | www.netgear.com | Patch, Product |
| kb.netgear.com/000070416/December-2025-NETGEAR-Security-Advisory | a2826606-91e7-4eb6-899e-8484bd4575d5 | kb.netgear.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: SmallS (en)
Additional Advisory Data
Solutions
CNA: NETGEAR R7000P has reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire this device and upgrade to a newer NETGEAR device for continued security support.
Workarounds
CNA: NETGEAR strongly recommends not to allow untrusted users to administer your device and protect it with strong password.