A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run.
This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
Configuration 14 (hide)
| AND |
|
Configuration 15 (hide)
| AND |
|
Configuration 16 (hide)
| AND |
|
Configuration 17 (hide)
| AND |
|
Configuration 18 (hide)
| AND |
|
History
21 Jan 2026, 19:29
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Netgear raxe450 Firmware
Netgear rax49s Netgear rax50v2 Netgear rax41 Netgear rax49s Firmware Netgear rax43v2 Netgear rax35v2 Firmware Netgear rax43 Netgear raxe500 Firmware Netgear rax43v2 Firmware Netgear raxe500 Netgear ms90 Netgear rs700 Firmware Netgear rax45 Netgear raxe450 Netgear rs700 Netgear rax50 Firmware Netgear rax50v2 Firmware Netgear rax54sv2 Netgear rax35v2 Netgear mr90 Firmware Netgear rax42 Firmware Netgear rax50 Netgear Netgear rax42v2 Firmware Netgear rax42v2 Netgear rax45v2 Firmware Netgear ms90 Firmware Netgear rax43 Firmware Netgear rax45v2 Netgear mr90 Netgear rax45 Firmware Netgear rax41 Firmware Netgear rax54sv2 Firmware Netgear rax41v2 Firmware Netgear rax41v2 Netgear rax42 |
|
| CWE | NVD-CWE-noinfo | |
| References | () https://kb.netgear.com/000070416/December-2025-NETGEAR-Security-Advisory - Patch, Vendor Advisory | |
| References | () https://www.netgear.com/support/product/RAX50 - Patch, Product | |
| References | () https://www.netgear.com/support/product/mr90 - Patch, Product | |
| References | () https://www.netgear.com/support/product/ms90 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax35v2 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax41 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax41v2 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax42 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax42v2 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax43 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax43v2 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax45 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax49s - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax50v2 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rax54sv2 - Patch, Product | |
| References | () https://www.netgear.com/support/product/raxe450 - Patch, Product | |
| References | () https://www.netgear.com/support/product/raxe500 - Patch, Product | |
| References | () https://www.netgear.com/support/product/rs700 - Patch, Product | |
| CPE | cpe:2.3:h:netgear:rax50:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:mr90_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax43:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax41v2:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:raxe450_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:mr90:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax43v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:ms90:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax45v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax49s:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax42v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax54sv2:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:raxe500_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax42v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax41_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax42_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:raxe500:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ms90_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax41:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax45_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax54sv2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax49s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax43_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax43v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax45:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax45v2:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax35v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax41v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax42:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax50v2:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:raxe450:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:rs700:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax50v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:rs700_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax35v2:-:*:*:*:*:*:*:* |
09 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 17:15
Updated : 2026-01-21 19:29
NVD link : CVE-2025-12946
Mitre link : CVE-2025-12946
CVE.ORG link : CVE-2025-12946
JSON object : View
Products Affected
netgear
- rax45v2
- raxe500_firmware
- rax49s_firmware
- rax35v2
- rax50v2_firmware
- rax50v2
- mr90
- rax54sv2_firmware
- rax41v2_firmware
- rax50_firmware
- rax42
- rax35v2_firmware
- ms90_firmware
- rax43
- ms90
- rax41_firmware
- rax42v2_firmware
- rax43v2
- rax41v2
- rax41
- rax49s
- raxe450
- rax45v2_firmware
- rax43v2_firmware
- rax45
- raxe500
- rax43_firmware
- rs700_firmware
- raxe450_firmware
- rs700
- rax45_firmware
- mr90_firmware
- rax50
- rax42_firmware
- rax42v2
- rax54sv2
CWE
