CVE-2025-12945: Improper input validation in NETGEAR Nighthawk router R7000P
An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modifications to the router software and functionality impacting its integrity. There is no additional impact to confidentiality or availability.
This issue affects R7000P: through 1.3.3.154.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR Nighthawk R7000Pto a version that resolves this vulnerability.Fixed in through 1.3.3.154
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12945?
CVE-2025-12945 has been identified as a high severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2025-12945?
To remediate CVE-2025-12945, users should update their NETGEAR Nighthawk R7000P routers to the latest firmware version available beyond 1.3.3.154.
What impact does CVE-2025-12945 have on my device?
CVE-2025-12945 allows authenticated administrators to execute arbitrary OS commands, potentially compromising the system.
Who is affected by CVE-2025-12945?
The NETGEAR Nighthawk R7000P router running firmware version 1.3.3.154 and earlier is affected by CVE-2025-12945.
Is remote access required to exploit CVE-2025-12945?
No, CVE-2025-12945 requires an authenticated admin account, meaning that an attacker needs to have admin access to exploit this vulnerability.