Input validation error in NETGEAR products - CVE-2025-12946
Published: December 10, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the speedtest feature. A remote attacker on the local network can pass specially crafted input to the application and execute arbitrary commands when speedtests are run.
Affected software
MS90
MR90
RAX41
RAX43
RAX35v2
RAX42
RAX45
RAX43v2
RAX45v2
RAX49S
RAX42v2
RAX50v2
RAX41v2
RAX54Sv2
RAXE450
RAXE500
RAX50
How to mitigate CVE-2025-12946
MS90 - update to 1.0.2.46
MR90 - update to 1.0.2.46
RAX41 - update to 1.0.17.142
RAX43 - update to 1.0.17.142
RAX35v2 - update to 1.0.17.142
RAX42 - update to 1.0.17.142
RAX45 - update to 1.0.17.142
RAX43v2 - update to 1.1.6.36
RAX45v2 - update to 1.1.6.36
RAX49S - update to 1.1.6.36
RAX42v2 - update to 1.1.6.36
RAX50v2 - update to 1.1.6.36
RAX41v2 - update to 1.1.6.36
RAX54Sv2 - update to 1.1.6.36
RAXE450 - update to 1.2.14.114
RAXE500 - update to 1.2.14.114
RAX50 - update to 1.2.14.114