CVE Feed

    Dashboard / CVE / CVE-2025-12946

    CVE-2025-12946

    A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.

    Published:Dec 9, 2025
    Last Modified:Feb 26, 2026
    EPS:Dec 9, 2025
    EPSS Score:0.00075
    CVSS Score:7.5

    Affected Products

    Vendor
    Netgear
    Product
    Mr90
    Vendor
    Netgear
    Product
    Mr90 Firmware
    Vendor
    Netgear
    Product
    Ms90
    Vendor
    Netgear
    Product
    Ms90 Firmware
    Vendor
    Netgear
    Product
    Rax35v2
    Vendor
    Netgear
    Product
    Rax35v2 Firmware
    Vendor
    Netgear
    Product
    Rax41
    Vendor
    Netgear
    Product
    Rax41 Firmware
    Vendor
    Netgear
    Product
    Rax41v2
    Vendor
    Netgear
    Product
    Rax41v2 Firmware
    Vendor
    Netgear
    Product
    Rax42
    Vendor
    Netgear
    Product
    Rax42 Firmware
    Vendor
    Netgear
    Product
    Rax42v2
    Vendor
    Netgear
    Product
    Rax42v2 Firmware
    Vendor
    Netgear
    Product
    Rax43
    Vendor
    Netgear
    Product
    Rax43 Firmware
    Vendor
    Netgear
    Product
    Rax43v2
    Vendor
    Netgear
    Product
    Rax43v2 Firmware
    Vendor
    Netgear
    Product
    Rax45
    Vendor
    Netgear
    Product
    Rax45 Firmware
    Vendor
    Netgear
    Product
    Rax45v2
    Vendor
    Netgear
    Product
    Rax45v2 Firmware
    Vendor
    Netgear
    Product
    Rax49s
    Vendor
    Netgear
    Product
    Rax49s Firmware
    Vendor
    Netgear
    Product
    Rax50
    Vendor
    Netgear
    Product
    Rax50 Firmware
    Vendor
    Netgear
    Product
    Rax50v2
    Vendor
    Netgear
    Product
    Rax50v2 Firmware
    Vendor
    Netgear
    Product
    Rax54sv2
    Vendor
    Netgear
    Product
    Rax54sv2 Firmware
    Vendor
    Netgear
    Product
    Raxe450
    Vendor
    Netgear
    Product
    Raxe450 Firmware
    Vendor
    Netgear
    Product
    Raxe500
    Vendor
    Netgear
    Product
    Raxe500 Firmware
    Vendor
    Netgear
    Product
    Rs700
    Vendor
    Netgear
    Product
    Rs700 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High