CVE-2025-12945 LOW

CVE-2025-12945: Improper input validation in NETGEAR Nighthawk router R7000P

Vendor Netgear
Product R7000P
Weakness CWE-20 · Input validation
Published December 9, 2025
Last update December 9, 2025

CVSS base score

1.1/10
Attack vector Adjacent
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber

What the vulnerability does

01Description

A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation. This issue affects R7000P: through 1.3.3.154.

Key dates

02Disclosure timeline

December 9, 2025 CVE published
December 9, 2025 Record updated