Improper input validation in NETGEAR Nighthawk routers

Summary

CVECVE-2025-12946
StatePUBLISHED
AssignerNETGEAR
Source PriorityCVE Program / NVD first with legacy fallback
Published2025-12-09 17:15:48 UTC
Updated2026-09-30 20:10:00 UTC
DescriptionA vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.

Risk And Classification

Primary CVSS: v4.0 4.4 MEDIUM from a2826606-91e7-4eb6-899e-8484bd4575d5

CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:D/RE:M/U:Amber

EPSS: 0.002930000 probability, percentile 0.197490000 (date 2026-10-01)

Problem Types: CWE-20 | NVD-CWE-noinfo | CWE-20 CWE-20 Improper Input Validation


VersionSourceTypeScoreSeverityVector
4.0a2826606-91e7-4eb6-899e-8484bd4575d5Secondary4.4MEDIUMCVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/C...
4.0CNACVSS4.4MEDIUMCVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/S...
3.1[email protected]Primary7.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0 Breakdown

Attack Vector
Adjacent
Attack Complexity
High
Attack Requirements
Present
Privileges Required
None
User Interaction
Active
Confidentiality
High
Integrity
High
Availability
High
Sub Conf.
None
Sub Integrity
None
Sub Availability
None

CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:D/RE:M/U:Amber

CVSS v3.1 Breakdown

Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Netgear Mr90 - All All All
Operating System Netgear Mr90 Firmware All All All All
Hardware Netgear Ms90 - All All All
Operating System Netgear Ms90 Firmware All All All All
Hardware Netgear Rax35v2 - All All All
Operating System Netgear Rax35v2 Firmware All All All All
Hardware Netgear Rax41 - All All All
Hardware Netgear Rax41v2 - All All All
Operating System Netgear Rax41v2 Firmware All All All All
Operating System Netgear Rax41 Firmware All All All All
Hardware Netgear Rax42 - All All All
Hardware Netgear Rax42v2 - All All All
Operating System Netgear Rax42v2 Firmware All All All All
Operating System Netgear Rax42 Firmware All All All All
Hardware Netgear Rax43 - All All All
Hardware Netgear Rax43v2 - All All All
Operating System Netgear Rax43v2 Firmware All All All All
Operating System Netgear Rax43 Firmware All All All All
Hardware Netgear Rax45 - All All All
Hardware Netgear Rax45v2 - All All All
Operating System Netgear Rax45v2 Firmware All All All All
Operating System Netgear Rax45 Firmware All All All All
Hardware Netgear Rax49s - All All All
Operating System Netgear Rax49s Firmware All All All All
Hardware Netgear Rax50 - All All All
Hardware Netgear Rax50v2 - All All All
Operating System Netgear Rax50v2 Firmware All All All All
Operating System Netgear Rax50 Firmware All All All All
Hardware Netgear Rax54sv2 - All All All
Operating System Netgear Rax54sv2 Firmware All All All All
Hardware Netgear Raxe450 - All All All
Operating System Netgear Raxe450 Firmware All All All All
Hardware Netgear Raxe500 - All All All
Operating System Netgear Raxe500 Firmware All All All All
Hardware Netgear Rs700 - All All All
Operating System Netgear Rs700 Firmware All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA NETGEAR RS700 affected 1.0.7.82 custom Not specified
CNA NETGEAR RAX54Sv2 affected V1.1.6.36 custom Not specified
CNA NETGEAR RAX41v2 affected V1.1.6.36 custom Not specified
CNA NETGEAR RAX50 affected V1.2.14.114 custom Not specified
CNA NETGEAR RAXE500 affected V1.2.14.114 custom Not specified
CNA NETGEAR RAX41 affected V1.0.17.142 custom Not specified
CNA NETGEAR RAX43 affected V1.0.17.142 custom Not specified
CNA NETGEAR RAX35v2 affected V1.0.17.142 custom Not specified
CNA NETGEAR RAXE450 affected V1.2.14.114 custom Not specified
CNA NETGEAR RAX43v2 affected V1.1.6.36 custom Not specified
CNA NETGEAR RAX42 affected V1.0.17.142 custom Not specified
CNA NETGEAR RAX45 affected V1.0.17.142 custom Not specified
CNA NETGEAR RAX50v2 affected V1.1.6.36 custom Not specified
CNA NETGEAR MR90 affected V1.0.2.46 custom Not specified
CNA NETGEAR RAX42v2 affected V1.1.6.36 custom Not specified
CNA NETGEAR RAX49S affected V1.1.6.36 custom Not specified
CNA NETGEAR MS90 affected V1.0.2.46 custom Not specified

References

ReferenceSourceLinkTags
www.netgear.com/support/product/rax42 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/raxe450 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax49s a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax54sv2 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax43 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax41v2 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/ms90 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/mr90 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax41 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/raxe500 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/RAX50 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax35v2 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax42v2 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax50v2 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
kb.netgear.com/000070416/December-2025-NETGEAR-Security-Advisory a2826606-91e7-4eb6-899e-8484bd4575d5 kb.netgear.com Patch, Vendor Advisory
www.netgear.com/support/product/rs700 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax45 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
www.netgear.com/support/product/rax43v2 a2826606-91e7-4eb6-899e-8484bd4575d5 www.netgear.com Patch, Product
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

CNA: molybdenum (en)

Additional Advisory Data

SourceTimeEvent
CNA2025-12-09T16:00:00.000Zpublished

Solutions

CNA: Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: RS700 firmware V1.0.9.6 or later RAX54Sv2/RAX45v2  firmware V1.1.6.36 or later https://www.netgear.com/support/product/rax54sv2 RAX41v2  firmware V1.1.6.36 or later https://www.netgear.com/support/product/rax41v2 RAX50  firmware V1.2.14.114 or later https://www.netgear.com/support/product/RAX50 RAXE500  firmware V1.2.14.114 or later https://www.netgear.com/support/product/raxe500 RAX41 firmware V1.0.17.142 or later https://www.netgear.com/support/product/rax41 RAX43 firmware V1.0.17.142 or later https://www.netgear.com/support/product/rax43 RAX35v2 firmware V1.0.17.142 or later https://www.netgear.com/support/product/RAX35v2 RAXE450 firmware V1.0.17.142 or later https://www.netgear.com/support/product/RAXE450 RAX43v2 firmware V1.1.6.36 or later https://www.netgear.com/support/product/RAX43v2 RAX42 firmware V1.0.17.142 or later https://www.netgear.com/support/product/RAX42 RAX45  firmware V1.0.17.142 or later https://www.netgear.com/support/product/RAX45 RAX50v2 firmware V1.1.6.36 or later https://www.netgear.com/support/product/RAX50v2 MR90 firmware V1.0.2.46 or later https://www.netgear.com/support/product/MR90 MS90 firmware V1.0.2.46 or later https://www.netgear.com/support/product/MS90 RAX42v2 firmware V1.1.6.36 or later https://www.netgear.com/support/product/RAX42v2 RAX49S firmware V1.1.6.36 or later https://www.netgear.com/support/product/RAX42v2

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report