Input validation error in NETGEAR products - CVE-2025-12946

 

Input validation error in NETGEAR products - CVE-2025-12946

Published: December 10, 2025


Vulnerability identifier: #VU119796
CSH Severity: Medium
CVSS v4: 7.3 [CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12946
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input in the speedtest feature. A remote attacker on the local network can pass specially crafted input to the application and execute arbitrary commands when speedtests are run.


Affected software

RS700
MS90
MR90
RAX41
RAX43
RAX35v2
RAX42
RAX45
RAX43v2
RAX45v2
RAX49S
RAX42v2
RAX50v2
RAX41v2
RAX54Sv2
RAXE450
RAXE500
RAX50

How to mitigate CVE-2025-12946

Install updates from vendor's website.

RS700 - update to 1.0.9.6
MS90 - update to 1.0.2.46
MR90 - update to 1.0.2.46
RAX41 - update to 1.0.17.142
RAX43 - update to 1.0.17.142
RAX35v2 - update to 1.0.17.142
RAX42 - update to 1.0.17.142
RAX45 - update to 1.0.17.142
RAX43v2 - update to 1.1.6.36
RAX45v2 - update to 1.1.6.36
RAX49S - update to 1.1.6.36
RAX42v2 - update to 1.1.6.36
RAX50v2 - update to 1.1.6.36
RAX41v2 - update to 1.1.6.36
RAX54Sv2 - update to 1.1.6.36
RAXE450 - update to 1.2.14.114
RAXE500 - update to 1.2.14.114
RAX50 - update to 1.2.14.114

External References

Related Security Bulletins