Description
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.
Problem types
CWE-20 Improper Input Validation
Product status
Any version
Any version before V1.1.6.36
Any version before V1.1.6.36
Any version before V1.2.14.114
Any version before V1.2.14.114
Any version before V1.0.17.142
Any version before V1.0.17.142
Any version before V1.0.17.142
Any version before V1.2.14.114
Any version before V1.1.6.36
Any version before V1.0.17.142
Any version before V1.0.17.142
Any version before V1.1.6.36
Any version before V1.0.2.46
Any version before V1.1.6.36
Any version before V1.1.6.36
Any version before V1.0.2.46
Timeline
| 2025-12-09: | published |
Credits
molybdenum
References
www.netgear.com/support/product/rs700
www.netgear.com/support/product/rax54sv2
www.netgear.com/support/product/rax41v2
www.netgear.com/support/product/RAX50
www.netgear.com/support/product/raxe500
www.netgear.com/support/product/rax41
www.netgear.com/support/product/rax43
www.netgear.com/support/product/rax35v2
www.netgear.com/support/product/raxe450
www.netgear.com/support/product/rax43v2
www.netgear.com/support/product/rax42
www.netgear.com/support/product/rax45
www.netgear.com/support/product/rax50v2
www.netgear.com/support/product/mr90
www.netgear.com/support/product/ms90
www.netgear.com/support/product/rax42v2
www.netgear.com/support/product/rax49s
kb.netgear.com/...16/December-2025-NETGEAR-Security-Advisory