---
id: CVE-2025-12946
title: >-
  A vulnerability in the speedtest feature of affected NETGEAR Nighthawk
  routers, caused by improper input validation, can allow attackers on the
  router's WAN side, using attacker-in-the-middle techniques (MiTM) to
  manipulate DNS responses…
summary: >-
  A vulnerability in the speedtest feature of affected NETGEAR Nighthawk
  routers, caused by improper input validation, can allow attackers on the
  router's WAN side, using attacker-in-the-middle techniques (MiTM) to
  manipulate DNS responses…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: netgear
product: rs700_firmware
affected:
  - rs700_firmware < 1.0.9.6
  - rax54sv2_firmware < 1.1.6.36
  - rax45v2_firmware < 1.1.6.36
  - rax41v2_firmware < 1.1.6.36
  - rax50_firmware < 1.2.14.114
  - raxe500_firmware < 1.2.14.114
  - rax41_firmware < 1.0.17.142
  - rax43_firmware < 1.0.17.142
  - rax35v2_firmware < 1.0.17.142
  - raxe450_firmware < 1.0.17.142
  - rax43v2_firmware < 1.1.6.36
  - rax42_firmware < 1.0.17.142
  - rax45_firmware < 1.0.17.142
  - rax50v2_firmware < 1.1.6.36
  - mr90_firmware < 1.0.2.46
  - ms90_firmware < 1.0.2.46
  - rax42v2_firmware < 1.1.6.36
  - rax49s_firmware < 1.1.6.36
patched:
  - rs700_firmware 1.0.9.6
  - rax54sv2_firmware 1.1.6.36
  - rax45v2_firmware 1.1.6.36
  - rax41v2_firmware 1.1.6.36
  - rax50_firmware 1.2.14.114
  - raxe500_firmware 1.2.14.114
  - rax41_firmware 1.0.17.142
  - rax43_firmware 1.0.17.142
  - rax35v2_firmware 1.0.17.142
  - raxe450_firmware 1.0.17.142
  - rax43v2_firmware 1.1.6.36
  - rax42_firmware 1.0.17.142
  - rax45_firmware 1.0.17.142
  - rax50v2_firmware 1.1.6.36
  - mr90_firmware 1.0.2.46
  - ms90_firmware 1.0.2.46
  - rax42v2_firmware 1.1.6.36
  - rax49s_firmware 1.1.6.36
published: '2025-12-09'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12946'
references:
  - url: 'https://kb.netgear.com/000070416/December-2025-NETGEAR-Security-Advisory'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/RAX50'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/mr90'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/ms90'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax35v2'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax41'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax41v2'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax42'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax42v2'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax43'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax43v2'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax45'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax49s'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax50v2'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rax54sv2'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/raxe450'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/raxe500'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
  - url: 'https://www.netgear.com/support/product/rs700'
    label: a2826606-91e7-4eb6-899e-8484bd4575d5
tags:
  - nvd
epss: 0.00293
epssPercentile: 0.1972
ingestedAt: '2026-09-30T20:23:19.441Z'
---

## Overview

A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. 



This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.

## Affected

- `rs700_firmware < 1.0.9.6`
- `rax54sv2_firmware < 1.1.6.36`
- `rax45v2_firmware < 1.1.6.36`
- `rax41v2_firmware < 1.1.6.36`
- `rax50_firmware < 1.2.14.114`
- `raxe500_firmware < 1.2.14.114`
- `rax41_firmware < 1.0.17.142`
- `rax43_firmware < 1.0.17.142`
- `rax35v2_firmware < 1.0.17.142`
- `raxe450_firmware < 1.0.17.142`
- `rax43v2_firmware < 1.1.6.36`
- `rax42_firmware < 1.0.17.142`
- `rax45_firmware < 1.0.17.142`
- `rax50v2_firmware < 1.1.6.36`
- `mr90_firmware < 1.0.2.46`
- `ms90_firmware < 1.0.2.46`
- `rax42v2_firmware < 1.1.6.36`
- `rax49s_firmware < 1.1.6.36`

## Remediation

Upgrade past the affected range:

- `rs700_firmware 1.0.9.6`
- `rax54sv2_firmware 1.1.6.36`
- `rax45v2_firmware 1.1.6.36`
- `rax41v2_firmware 1.1.6.36`
- `rax50_firmware 1.2.14.114`
- `raxe500_firmware 1.2.14.114`
- `rax41_firmware 1.0.17.142`
- `rax43_firmware 1.0.17.142`
- `rax35v2_firmware 1.0.17.142`
- `raxe450_firmware 1.0.17.142`
- `rax43v2_firmware 1.1.6.36`
- `rax42_firmware 1.0.17.142`
- `rax45_firmware 1.0.17.142`
- `rax50v2_firmware 1.1.6.36`
- `mr90_firmware 1.0.2.46`
- `ms90_firmware 1.0.2.46`
- `rax42v2_firmware 1.1.6.36`
- `rax49s_firmware 1.1.6.36`
