{"id": "CVE-2025-12946", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "ADJACENT_NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.6}], "cvssMetricV40": [{"type": "Secondary", "source": "a2826606-91e7-4eb6-899e-8484bd4575d5", "cvssData": {"Safety": "NEGLIGIBLE", "version": "4.0", "Recovery": "AUTOMATIC", "baseScore": 4.4, "Automatable": "NO", "attackVector": "ADJACENT", "baseSeverity": "MEDIUM", "valueDensity": "DIFFUSE", "vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:D/RE:M/U:Amber", "exploitMaturity": "UNREPORTED", "providerUrgency": "AMBER", "userInteraction": "ACTIVE", "attackComplexity": "HIGH", "attackRequirements": "PRESENT", "privilegesRequired": "NONE", "subIntegrityImpact": "NONE", "vulnIntegrityImpact": "HIGH", "integrityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "availabilityRequirement": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "subConfidentialityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "confidentialityRequirement": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "vulnerabilityResponseEffort": "MODERATE", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED"}}]}, "published": "2025-12-09T17:15:48.820", "references": [{"url": "https://kb.netgear.com/000070416/December-2025-NETGEAR-Security-Advisory", "tags": ["Patch", "Vendor Advisory"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/RAX50", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/mr90", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/ms90", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax35v2", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax41", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax41v2", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax42", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax42v2", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax43", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax43v2", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax45", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax49s", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax50v2", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rax54sv2", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/raxe450", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/raxe500", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}, {"url": "https://www.netgear.com/support/product/rs700", "tags": ["Patch", "Product"], "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Secondary", "source": "a2826606-91e7-4eb6-899e-8484bd4575d5", "description": [{"lang": "en", "value": "CWE-20"}]}, {"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. \n\n\n\nThis issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46;\u202fRAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36."}], "lastModified": "2026-01-21T19:29:14.017", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rs700_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C3AE8FD9-1FC9-4DF0-B22B-B482980EEDA8", "versionEndExcluding": "1.0.9.6"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rs700:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "20BFC36A-1819-4878-A004-9851290B203F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax54sv2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83DB8165-F9DC-4086-91AF-9C4298FECBCC", "versionEndExcluding": "1.1.6.36"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax54sv2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B9FCC230-8A49-4C8C-BB53-DD703996F4DA"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax45v2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F6C69CA-30D0-4753-915B-9E5A15F10E2A", "versionEndExcluding": "1.1.6.36"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax45v2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AD5E8B48-66CB-4D9B-89C3-DA5F1A7B74F3"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax41v2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BEC93BCF-E89C-49A9-9631-1666E6FF4E21", "versionEndExcluding": "1.1.6.36"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax41v2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "138DD7E4-528F-4984-ACD7-E18379C4FF7C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24ADEE5B-3DA1-4BA7-99BC-64746B6E797A", "versionEndExcluding": "1.2.14.114"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax50:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C430976E-24C0-4EA7-BF54-F9C188AB9C01"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:raxe500_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B75B005E-469A-4AB4-A0F5-D0067D66FFA3", "versionEndExcluding": "1.2.14.114"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:raxe500:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6D23ADF0-05B4-4163-9666-3F470FB19E01"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax41_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "26F72A55-78AE-47E4-B18B-E042FC3B2EC6", "versionEndExcluding": "1.0.17.142"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax41:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C52C7C17-08C5-47CE-A5D5-640C6B9DB82C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax43_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C774BE3-68EE-4FAB-91AF-F62BB671AE49", "versionEndExcluding": "1.0.17.142"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax43:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "178BB386-F66C-4CE8-9283-37D22B304691"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax35v2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "272325DB-336A-4278-A6B9-07B0FF413C85", "versionEndExcluding": "1.0.17.142"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax35v2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9358B2F2-D24E-434D-AEE5-6CE093598793"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:raxe450_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6B5D898-8F61-429C-A092-4A3B1730E40D", "versionEndExcluding": "1.0.17.142"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:raxe450:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "67D7EC2C-E443-4749-854E-5BC057CA6B06"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax43v2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01763B66-6177-4EDC-BD12-54D931DFDB2F", "versionEndExcluding": "1.1.6.36"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax43v2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6E165736-5E8D-4DDB-B157-99723FE20BD2"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax42_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7838CEA1-0B9F-40B7-AE11-567E9223F011", "versionEndExcluding": "1.0.17.142"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax42:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D83182AB-E726-4371-B092-FA1920408FED"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax45_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C93981C6-FF9B-46D2-836A-CFAF47EC87FF", "versionEndExcluding": "1.0.17.142"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax45:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4B08BD69-CDCC-4CEB-B887-4E47D2B45D26"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax50v2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92ED39F8-F270-46EA-8947-F855FEFD5CF5", "versionEndExcluding": "1.1.6.36"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax50v2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "59381950-4DC4-4FD7-B3DB-D950DDA5C591"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:mr90_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC405D96-56D5-437D-9F9A-B101981BEED1", "versionEndExcluding": "1.0.2.46"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:mr90:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "37B02AF9-8E7C-4916-8D7A-7A920AB95593"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:ms90_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B0D8D94-1B29-4629-BC9F-29F18E3A13FA", "versionEndExcluding": "1.0.2.46"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:ms90:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5C6AA9FB-3B52-450A-9DF5-CBD32CA17ED3"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax42v2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23B8F4EF-7E41-4686-9138-77FE95114F8B", "versionEndExcluding": "1.1.6.36"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax42v2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D61EA1E9-FB8C-4E79-8A07-7B5E79DCB70A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:netgear:rax49s_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EAC35BB2-E9D2-4097-BA74-3FDCFD83741B", "versionEndExcluding": "1.1.6.36"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:netgear:rax49s:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "85511EF7-8F04-4DB7-8CF3-2F888A0A94C5"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "a2826606-91e7-4eb6-899e-8484bd4575d5"}