Home

Description

A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation. This issue affects R7000P: through 1.3.3.154.

PUBLISHED Reserved 2025-11-10 | Published 2025-12-09 | Updated 2025-12-09 | Assigner NETGEAR




LOW: 1.1CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version
affected

Credits

SmallS finder

References

www.netgear.com/support/product/r7000p product

kb.netgear.com/...16/December-2025-NETGEAR-Security-Advisory vendor-advisory

cve.org (CVE-2025-12945)

nvd.nist.gov (CVE-2025-12945)

Download JSON