CVE-2025-12946: Improper input validation in NETGEAR Nighthawk routers

Published Dec 9, 2025
·
Updated

A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run.

This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.

Affected Software

53 affected components
Netgear Nighthawk<1.0.7.82
Netgear Nighthawk RAX54Sv2<V1.1.6.36
Netgear Nighthawk RAX41v2<V1.1.6.36
Netgear Nighthawk RAX50<V1.2.14.114
Netgear Nighthawk RAXE500<V1.2.14.114
Netgear Nighthawk RAX41<V1.0.17.142
Netgear Nighthawk RAX43<V1.0.17.142
Netgear Nighthawk RAX35v2<V1.0.17.142
Netgear Nighthawk RAXE450<V1.2.14.114
Netgear Nighthawk RAX43v2<V1.1.6.36
Netgear Nighthawk RAX42<V1.0.17.142
Netgear Nighthawk RAX45<V1.0.17.142
Netgear Nighthawk RAX50v2<V1.1.6.36
Netgear Nighthawk MR90<V1.0.2.46
Netgear Nighthawk MS90<V1.0.2.46
Netgear Nighthawk RAX42v2<V1.1.6.36
Netgear Nighthawk RAX49S<V1.1.6.36
All of the following
Netgear Rs700 Firmware<1.0.9.6
Netgear RS700
All of the following
Netgear Rax54sv2 Firmware<1.1.6.36
Netgear RAX54Sv2
All of the following
Netgear Rax45v2 Firmware<1.1.6.36
Netgear Rax45v2
All of the following
Netgear Rax41v2 Firmware<1.1.6.36
Netgear RAX41v2
All of the following
Netgear Rax50 Firmware<1.2.14.114
Netgear RAX50
All of the following
Netgear Raxe500 Firmware<1.2.14.114
Netgear RAXE500
All of the following
Netgear Rax41 Firmware<1.0.17.142
Netgear RAX41
All of the following
Netgear Rax43 Firmware<1.0.17.142
Netgear RAX43
All of the following
Netgear Rax35v2 Firmware<1.0.17.142
Netgear RAX35v2
All of the following
Netgear Raxe450 Firmware<1.0.17.142
Netgear RAXE450
All of the following
Netgear Rax43v2 Firmware<1.1.6.36
Netgear RAX43v2
All of the following
Netgear Rax42 Firmware<1.0.17.142
Netgear RAX42
All of the following
Netgear Rax45 Firmware<1.0.17.142
Netgear RAX45
All of the following
Netgear Rax50v2 Firmware<1.1.6.36
Netgear RAX50v2
All of the following
Netgear Mr90 Firmware<1.0.2.46
Netgear MR90
All of the following
Netgear Ms90 Firmware<1.0.2.46
Netgear MS90
All of the following
Netgear Rax42v2 Firmware<1.1.6.36
Netgear RAX42v2
All of the following
Netgear Rax49s Firmware<1.1.6.36
Netgear RAX49S

Remediation

Information

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: RS700 firmware V1.0.9.6 or later RAX54Sv2/RAX45v2  firmware V1.1.6.36 or later https://www.netgear.com/support/product/rax54sv2 RAX41v2  firmware V1.1.6.36 or later https://www.netgear.com/support/product/rax41v2 RAX50  firmware V1.2.14.114 or later https://www.netgear.com/support/product/RAX50 RAXE500  firmware V1.2.14.114 or later https://www.netgear.com/support/product/raxe500 RAX41 firmware V1.0.17.142 or later https://www.netgear.com/support/product/rax41 RAX43 firmware V1.0.17.142 or later https://www.netgear.com/support/product/rax43 RAX35v2 firmware V1.0.17.142 or later https://www.netgear.com/support/product/RAX35v2 RAXE450 firmware V1.0.17.142 or later https://www.netgear.com/support/product/RAXE450 RAX43v2 firmware V1.1.6.36 or later https://www.netgear.com/support/product/RAX43v2 RAX42 firmware V1.0.17.142 or later https://www.netgear.com/support/product/RAX42 RAX45  firmware V1.0.17.142 or later https://www.netgear.com/support/product/RAX45 RAX50v2 firmware V1.1.6.36 or later https://www.netgear.com/support/product/RAX50v2 MR90 firmware V1.0.2.46 or later https://www.netgear.com/support/product/MR90 MS90 firmware V1.0.2.46 or later https://www.netgear.com/support/product/MS90 RAX42v2 firmware V1.1.6.36 or later https://www.netgear.com/support/product/RAX42v2 RAX49S firmware V1.1.6.36 or later https://www.netgear.com/support/product/RAX42v2

Event History

Dec 9, 2025
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-12946?

CVE-2025-12946 is classified as a high-severity vulnerability due to its potential to allow remote code execution.

2

How do I fix CVE-2025-12946?

To fix CVE-2025-12946, update affected NETGEAR Nighthawk routers to the latest firmware version.

3

Which NETGEAR devices are affected by CVE-2025-12946?

NETGEAR Nighthawk routers including RAX54Sv2, RAX41v2, and several others up to version limitations are affected by CVE-2025-12946.

4

What causes the vulnerability CVE-2025-12946?

The vulnerability CVE-2025-12946 is caused by improper input validation in the speedtest feature of the affected NETGEAR Nighthawk routers.

5

Can CVE-2025-12946 be exploited remotely?

Yes, CVE-2025-12946 can be exploited remotely by attackers on the router's WAN side using man-in-the-middle techniques.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203