2.4lowLow

CVE-2025-12945

Netgear R7000p Firmware

An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modifications to the router software and functionality impacting its integrity. There is no additional impact to confidentiality or availability. This issue affects R7000P: through 1.3.3.154.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable only from the same local or logical network.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an administrative account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
2.4 (v3.1)
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CVSS v4
1.1
Weakness
CWE-20
Assigned by
a2826606-91e7-4eb6-899e-8484bd4575d5

Dates

Published
2025-12-09
Last modified
2026-08-26
Sources
NVD

Affected products

  • Netgear R7000p Firmware- 1.3.3.154
  • Netgear R7000pall versions

As listed in the NVD configuration data. Not a statement about your estate.

References