NETGEAR's Product Security Team has assessed the following product vulnerabilities and provided guidance to address these vulnerabilities in the table below.
Because firmware updates contain security fixes, bug fixes, and new features for your products, we strongly advise you to enable automatic firmware updates on supported devices. For older products, we advise you to download and install new firmware updates as soon as possible or follow the guidance provided for devices that require other remediation steps.
| Affected Products | Issue | Recommendation | Fixed in Firmware |
|
CVE-2025-12940: Login credentials are inadvertently recorded in logs. Users with access to the syslog server are able to view these credentials. Acknowledgments: filiperfonseca |
Enable Automatic Updates. Update to the latest firmware. |
||
|
CVE-2025-12942: Improper Input Validation vulnerability allows unauthenticated attackers connected to LAN to perform MiTM attacks and take control of DNS Server to perform command execution. Acknowledgments: dcmtruman |
Enable Automatic Updates. Update to the latest firmware. |
||
|
CVE-2025-12943: Improper certificate validation in firmware update logic allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device. Acknowledgments: rqu4 |
Enable Automatic Updates. Update to the latest firmware. |
||
|
CVE-2025-12944: Improper input validation allows attackers with direct network access to the device to potentially execute code on the device. Acknowledgments: crixer |
Update to the latest firmware. |
Acknowledgments
NETGEAR thanks the security researchers and partners who responsibly disclosed these vulnerabilities.
Disclaimer
This document is provided on an "as is" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information in the document or materials linked to the document is at your own risk. NETGEAR reserves the right to change or update this document at any time. NETGEAR expects to update this document as new information becomes available.
The above-listed vulnerabilities remain if you do not complete all recommended steps. NETGEAR is not responsible for any consequences that could have been avoided by following the recommendations in this notification.
Revision History
2025-11-11: Initial publication