7.5

CVE-2025-12946

A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. 



This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetgearRs700 Firmware Version < 1.0.9.6
   NetgearRs700 Version-
NetgearRax54sv2 Firmware Version < 1.1.6.36
   NetgearRax54sv2 Version-
NetgearRax45v2 Firmware Version < 1.1.6.36
   NetgearRax45v2 Version-
NetgearRax41v2 Firmware Version < 1.1.6.36
   NetgearRax41v2 Version-
NetgearRax50 Firmware Version < 1.2.14.114
   NetgearRax50 Version-
NetgearRaxe500 Firmware Version < 1.2.14.114
   NetgearRaxe500 Version-
NetgearRax41 Firmware Version < 1.0.17.142
   NetgearRax41 Version-
NetgearRax43 Firmware Version < 1.0.17.142
   NetgearRax43 Version-
NetgearRax35v2 Firmware Version < 1.0.17.142
   NetgearRax35v2 Version-
NetgearRaxe450 Firmware Version < 1.0.17.142
   NetgearRaxe450 Version-
NetgearRax43v2 Firmware Version < 1.1.6.36
   NetgearRax43v2 Version-
NetgearRax42 Firmware Version < 1.0.17.142
   NetgearRax42 Version-
NetgearRax45 Firmware Version < 1.0.17.142
   NetgearRax45 Version-
NetgearRax50v2 Firmware Version < 1.1.6.36
   NetgearRax50v2 Version-
NetgearMr90 Firmware Version < 1.0.2.46
   NetgearMr90 Version-
NetgearMs90 Firmware Version < 1.0.2.46
   NetgearMs90 Version-
NetgearRax42v2 Firmware Version < 1.1.6.36
   NetgearRax42v2 Version-
NetgearRax49s Firmware Version < 1.1.6.36
   NetgearRax49s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.21
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
a2826606-91e7-4eb6-899e-8484bd4575d5 4.4 0 0
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:D/RE:M/U:Amber
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.