CVE-2025-12946High· 7.5▾ TwilightA vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run.
This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.
rs700_firmware < 1.0.9.6rax54sv2_firmware < 1.1.6.36rax45v2_firmware < 1.1.6.36rax41v2_firmware < 1.1.6.36rax50_firmware < 1.2.14.114raxe500_firmware < 1.2.14.114rax41_firmware < 1.0.17.142rax43_firmware < 1.0.17.142rax35v2_firmware < 1.0.17.142raxe450_firmware < 1.0.17.142rax43v2_firmware < 1.1.6.36rax42_firmware < 1.0.17.142rax45_firmware < 1.0.17.142rax50v2_firmware < 1.1.6.36mr90_firmware < 1.0.2.46ms90_firmware < 1.0.2.46rax42v2_firmware < 1.1.6.36rax49s_firmware < 1.1.6.36Upgrade past the affected range:
rs700_firmware 1.0.9.6rax54sv2_firmware 1.1.6.36rax45v2_firmware 1.1.6.36rax41v2_firmware 1.1.6.36rax50_firmware 1.2.14.114raxe500_firmware 1.2.14.114rax41_firmware 1.0.17.142rax43_firmware 1.0.17.142rax35v2_firmware 1.0.17.142raxe450_firmware 1.0.17.142rax43v2_firmware 1.1.6.36rax42_firmware 1.0.17.142rax45_firmware 1.0.17.142rax50v2_firmware 1.1.6.36mr90_firmware 1.0.2.46ms90_firmware 1.0.2.46rax42v2_firmware 1.1.6.36rax49s_firmware 1.1.6.36Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12945Low· 2.4An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modif…
CVE-2026-9214Medium· 4.5Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-11738Medium· 4.4Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-11737Medium· 4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
CVE-2026-11736Medium· 4.9A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
CVE-2025-48612High· 7.8In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to improper input validation