Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-12946

24
FAUCET Score

CVE-2025-12946 is a critical vulnerability in the speedtest feature of various NETGEAR Nighthawk routers, including the RS700, RAX54Sv2, and RAX50 series, stemming from improper input validation. This flaw allows attackers on the WAN side to execute arbitrary commands by manipulating DNS responses during a speedtest, utilizing attacker-in-the-middle techniques. With a CVSS score of 7.5 (HIGH), the vulnerability presents a significant risk due to its network-adjacent attack vector and high impact on confidentiality, integrity, and availability. While no active exploitation, public exploits (Metasploit, Nuclei, ExploitDB), or significant community discussion have been observed, affected organizations should prioritize patching to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.0.9.6CPE matchmatch criteria
cpe:2.3:o:netgear:rs700_firmware:*:*:*:*:*:*:*:*
< 1.1.6.36CPE matchmatch criteria
cpe:2.3:o:netgear:rax54sv2_firmware:*:*:*:*:*:*:*:*
< 1.1.6.36CPE matchmatch criteria
cpe:2.3:o:netgear:rax45v2_firmware:*:*:*:*:*:*:*:*
< 1.1.6.36CPE matchmatch criteria
cpe:2.3:o:netgear:rax41v2_firmware:*:*:*:*:*:*:*:*
< 1.2.14.114CPE matchmatch criteria
cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

4.4MEDIUM

CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:D/RE:M/U:Amber

Attack Vector
ADJACENT
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 25th percentile among its peer group of 239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

kb.netgear.com / 000070416/December-2025-NETGEAR-Security-Advisory
PatchVendor Advisory
netgear.com / support/product/mr90
PatchProduct
netgear.com / support/product/ms90
PatchProduct
netgear.com / support/product/rax35v2
PatchProduct
netgear.com / support/product/rax41
PatchProduct
netgear.com / support/product/rax41v2
PatchProduct
netgear.com / support/product/rax42
PatchProduct
netgear.com / support/product/rax42v2
PatchProduct
netgear.com / support/product/rax43
PatchProduct
netgear.com / support/product/rax43v2
PatchProduct
netgear.com / support/product/rax45
PatchProduct
netgear.com / support/product/rax49s
PatchProduct
netgear.com / support/product/RAX50
PatchProduct
netgear.com / support/product/rax50v2
PatchProduct
netgear.com / support/product/rax54sv2
PatchProduct
netgear.com / support/product/raxe450
PatchProduct
netgear.com / support/product/raxe500
PatchProduct
netgear.com / support/product/rs700
PatchProduct