CVE-2025-12945: Improper input validation in NETGEAR Nighthawk router R7000P

Published Dec 9, 2025
·
Updated

A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation.

This issue affects R7000P: through 1.3.3.154.

Affected Software

3 affected components
Netgear Nighthawk R7000P<=1.3.3.154
All of the following
Netgear R7000p Firmware<=1.3.3.154
Netgear R7000P

Remediation

Information

NETGEAR R7000P has reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire this device and upgrade to a newer NETGEAR device for continued security support.

Event History

Dec 9, 2025
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-12945?

CVE-2025-12945 has been identified as a high severity vulnerability due to the potential for OS command injection.

2

How do I fix CVE-2025-12945?

To remediate CVE-2025-12945, users should update their NETGEAR Nighthawk R7000P routers to the latest firmware version available beyond 1.3.3.154.

3

What impact does CVE-2025-12945 have on my device?

CVE-2025-12945 allows authenticated administrators to execute arbitrary OS commands, potentially compromising the system.

4

Who is affected by CVE-2025-12945?

The NETGEAR Nighthawk R7000P router running firmware version 1.3.3.154 and earlier is affected by CVE-2025-12945.

5

Is remote access required to exploit CVE-2025-12945?

No, CVE-2025-12945 requires an authenticated admin account, meaning that an attacker needs to have admin access to exploit this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203