2.4lowLow
CVE-2025-12945
Netgear R7000p Firmware
An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modifications to the router software and functionality impacting its integrity. There is no additional impact to confidentiality or availability. This issue affects R7000P: through 1.3.3.154.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable only from the same local or logical network.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an administrative account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 2.4 (v3.1)
- Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N- CVSS v4
- 1.1
- Weakness
- CWE-20
- Assigned by
- a2826606-91e7-4eb6-899e-8484bd4575d5
Dates
- Published
- 2025-12-09
- Last modified
- 2026-08-26
- Sources
- NVD
Affected products
- Netgear R7000p Firmware- 1.3.3.154
- Netgear R7000pall versions
As listed in the NVD configuration data. Not a statement about your estate.