CVE-2025-12944 MEDIUM

CVE-2025-12944: Improper input validation in NETGEAR DGN2200v4

Vendor Netgear
Product DGN2200v4
Weakness CWE-20 · Input validation
Published November 11, 2025
Last update February 26, 2026

CVSS base score

6.8/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/AU:N/R:A/V:D/RE:L/U:Amber

What the vulnerability does

01Description

Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network access to the device to potentially execute code on the device. Please check the firmware version and update to the latest. Fixed in:  DGN2200v4 firmware 1.0.0.132 or later

Key dates

02Disclosure timeline

November 11, 2025 CVE published
February 26, 2026 Record updated