Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform MiTM attacks and control over DNS Server to perform command execution.This issue affects R6260: through 1.1.0.86; R6850: through 1.1.0.86.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070355/NETGEAR-Security-Advisories-November-2025 | Vendor Advisory |
| https://www.netgear.com/support/product/r6260 | Product |
| https://www.netgear.com/support/product/r6850 | Product |
Configurations
History
08 Dec 2025, 14:26
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://kb.netgear.com/000070355/NETGEAR-Security-Advisories-November-2025 - Vendor Advisory | |
| References | () https://www.netgear.com/support/product/r6260 - Product | |
| References | () https://www.netgear.com/support/product/r6850 - Product | |
| CPE | cpe:2.3:o:netgear:r6850_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6260:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6850:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6260_firmware:*:*:*:*:*:*:*:* |
|
| First Time |
Netgear r6260
Netgear r6850 Firmware Netgear r6260 Firmware Netgear r6850 Netgear |
11 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-11 17:15
Updated : 2025-12-08 14:26
NVD link : CVE-2025-12942
Mitre link : CVE-2025-12942
CVE.ORG link : CVE-2025-12942
JSON object : View
Products Affected
netgear
- r6850_firmware
- r6850
- r6260_firmware
- r6260
CWE
CWE-20
Improper Input Validation
