PT-2025-50104 · NetGear · Netgear Nighthawk R7000

Smalls

·

Published

2025-12-09

·

Updated

2025-12-14

·

CVE-2025-12945

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR Nighthawk R7000P versions through 1.3.3.154
Description A flaw exists in NETGEAR Nighthawk R7000P routers that allows an authenticated administrator to execute OS command injections. This is caused by insufficient input validation. The vulnerability allows for the execution of arbitrary commands on the underlying operating system.
Recommendations Update to a version later than 1.3.3.154.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-12945

Affected Products

Netgear Nighthawk R7000