Improper Certificate Validation in NETGEAR Nighthawk Routers
CVE-2025-12943

5.2MEDIUM

Key Information:

Vendor

Netgear

Vendor
CVE Published:
11 November 2025

What is CVE-2025-12943?

A vulnerability exists in the firmware update logic of NETGEAR's Nighthawk AX5 and AXE7800 routers due to improper certificate validation. This flaw can be exploited by attackers who can intercept and manipulate traffic directed to the device, allowing them to execute arbitrary commands. Users are advised to verify their firmware versions and ensure they have the latest updates installed to mitigate any potential threats.

Affected Version(s)

RAX30 0 < 1.0.10.95

RAXE300 0 < 1.0.9.82

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rqu4
.