{"id":"CVE-2025-12946","title":"A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses…","summary":"A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-20"],"vendor":"netgear","product":"rs700_firmware","affected":["rs700_firmware < 1.0.9.6","rax54sv2_firmware < 1.1.6.36","rax45v2_firmware < 1.1.6.36","rax41v2_firmware < 1.1.6.36","rax50_firmware < 1.2.14.114","raxe500_firmware < 1.2.14.114","rax41_firmware < 1.0.17.142","rax43_firmware < 1.0.17.142","rax35v2_firmware < 1.0.17.142","raxe450_firmware < 1.0.17.142","rax43v2_firmware < 1.1.6.36","rax42_firmware < 1.0.17.142","rax45_firmware < 1.0.17.142","rax50v2_firmware < 1.1.6.36","mr90_firmware < 1.0.2.46","ms90_firmware < 1.0.2.46","rax42v2_firmware < 1.1.6.36","rax49s_firmware < 1.1.6.36"],"patched":["rs700_firmware 1.0.9.6","rax54sv2_firmware 1.1.6.36","rax45v2_firmware 1.1.6.36","rax41v2_firmware 1.1.6.36","rax50_firmware 1.2.14.114","raxe500_firmware 1.2.14.114","rax41_firmware 1.0.17.142","rax43_firmware 1.0.17.142","rax35v2_firmware 1.0.17.142","raxe450_firmware 1.0.17.142","rax43v2_firmware 1.1.6.36","rax42_firmware 1.0.17.142","rax45_firmware 1.0.17.142","rax50v2_firmware 1.1.6.36","mr90_firmware 1.0.2.46","ms90_firmware 1.0.2.46","rax42v2_firmware 1.1.6.36","rax49s_firmware 1.1.6.36"],"published":"2025-12-09","updated":"2026-09-30","sourceUpdated":"2026-09-30T20:10:00.247","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-12946","references":[{"url":"https://kb.netgear.com/000070416/December-2025-NETGEAR-Security-Advisory","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/RAX50","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/mr90","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/ms90","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax35v2","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax41","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax41v2","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax42","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax42v2","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax43","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax43v2","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax45","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax49s","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax50v2","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rax54sv2","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/raxe450","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/raxe500","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"},{"url":"https://www.netgear.com/support/product/rs700","label":"a2826606-91e7-4eb6-899e-8484bd4575d5"}],"tags":["nvd"],"epss":0.00293,"epssPercentile":0.1972,"ingestedAt":"2026-09-30T20:23:19.441Z","slug":"CVE-2025-12946","body":"## Overview\n\nA vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. \n\n\n\nThis issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.\n\n## Affected\n\n- `rs700_firmware < 1.0.9.6`\n- `rax54sv2_firmware < 1.1.6.36`\n- `rax45v2_firmware < 1.1.6.36`\n- `rax41v2_firmware < 1.1.6.36`\n- `rax50_firmware < 1.2.14.114`\n- `raxe500_firmware < 1.2.14.114`\n- `rax41_firmware < 1.0.17.142`\n- `rax43_firmware < 1.0.17.142`\n- `rax35v2_firmware < 1.0.17.142`\n- `raxe450_firmware < 1.0.17.142`\n- `rax43v2_firmware < 1.1.6.36`\n- `rax42_firmware < 1.0.17.142`\n- `rax45_firmware < 1.0.17.142`\n- `rax50v2_firmware < 1.1.6.36`\n- `mr90_firmware < 1.0.2.46`\n- `ms90_firmware < 1.0.2.46`\n- `rax42v2_firmware < 1.1.6.36`\n- `rax49s_firmware < 1.1.6.36`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `rs700_firmware 1.0.9.6`\n- `rax54sv2_firmware 1.1.6.36`\n- `rax45v2_firmware 1.1.6.36`\n- `rax41v2_firmware 1.1.6.36`\n- `rax50_firmware 1.2.14.114`\n- `raxe500_firmware 1.2.14.114`\n- `rax41_firmware 1.0.17.142`\n- `rax43_firmware 1.0.17.142`\n- `rax35v2_firmware 1.0.17.142`\n- `raxe450_firmware 1.0.17.142`\n- `rax43v2_firmware 1.1.6.36`\n- `rax42_firmware 1.0.17.142`\n- `rax45_firmware 1.0.17.142`\n- `rax50v2_firmware 1.1.6.36`\n- `mr90_firmware 1.0.2.46`\n- `ms90_firmware 1.0.2.46`\n- `rax42v2_firmware 1.1.6.36`\n- `rax49s_firmware 1.1.6.36`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}