Junglewise Threat Intelligence

CVE-2025-12945: NETGEAR Nighthawk R7000P command injection in configuration

CVE-2025-12945 · Severity: low · CVSS 2.4 · Published 2025-12-09

Technologies: NETGEAR R7000P. Vendors: NETGEAR.

Executive brief

The NETGEAR Nighthawk R7000P is a wireless router used to provide network connectivity in homes and small offices. An authenticated administrator with access to the device's management interface can exploit improper input validation to execute arbitrary operating system commands, potentially compromising the router's integrity and allowing unauthorized modifications to its configuration and functionality. Since the R7000P has reached end-of-service, no security updates are available.

Technical details

The vulnerability is an OS command injection flaw caused by improper input validation in the NETGEAR Nighthawk R7000P router firmware. The attack requires an authenticated administrator with local network access to the device's management interface. An attacker with these privileges can inject shell commands through an unvalidated input field, leading to arbitrary command execution with router privileges. This allows modification of router configuration, software, and functionality. The vulnerability affects R7000P firmware versions through 1.3.3.154; no patches are available as the product has reached end-of-support status.

Affected products

  • NETGEAR Nighthawk R7000P through 1.3.3.154

Timeline

  • 2025-12-09: disclosed
  • other: Product has reached end-of-support; no security updates planned

References