CVE-2025-12946: Improper input validation in NETGEAR Nighthawk routers
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run.
This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.
Affected Software
Remediation
Information
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12946?
CVE-2025-12946 is classified as a high-severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2025-12946?
To fix CVE-2025-12946, update affected NETGEAR Nighthawk routers to the latest firmware version.
Which NETGEAR devices are affected by CVE-2025-12946?
NETGEAR Nighthawk routers including RAX54Sv2, RAX41v2, and several others up to version limitations are affected by CVE-2025-12946.
What causes the vulnerability CVE-2025-12946?
The vulnerability CVE-2025-12946 is caused by improper input validation in the speedtest feature of the affected NETGEAR Nighthawk routers.
Can CVE-2025-12946 be exploited remotely?
Yes, CVE-2025-12946 can be exploited remotely by attackers on the router's WAN side using man-in-the-middle techniques.