This issue affects R7000P: through 1.3.3.154.
No analysis available yet.
Vendor Solution
NETGEAR R7000P has reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire this device and upgrade to a newer NETGEAR device for continued security support.
Vendor Workaround
NETGEAR strongly recommends not to allow untrusted users to administer your device and protect it with strong password.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation. This issue affects R7000P: through 1.3.3.154. | An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modifications to the router software and functionality impacting its integrity. There is no additional impact to confidentiality or availability. This issue affects R7000P: through 1.3.3.154. |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 16 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear r7000p Firmware
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgear r7000p Firmware
|
|
| Metrics |
cvssV3_1
|
Tue, 09 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation. This issue affects R7000P: through 1.3.3.154. | |
| Title | Improper input validation in NETGEAR Nighthawk router R7000P | |
| First Time appeared |
Netgear
Netgear r7000p |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:h:netgear:r7000p:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netgear
Netgear r7000p |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NETGEAR
Published:
Updated: 2026-08-26T16:17:50.127Z
Reserved: 2025-11-10T08:26:25.516Z
Link: CVE-2025-12945
Updated: 2025-12-09T20:22:24.868Z
Status : Modified
Published: 2025-12-09T17:15:48.647
Modified: 2026-08-26T17:16:46.000
Link: CVE-2025-12945
No data.
OpenCVE Enrichment
No data.
-
CWE-20
Improper Input Validation
- NVD-CWE-noinfo