CVE-2025-12943 Details
Description
Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device. Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update to the latest. Fixed in: RAX30 firmware 1.0.14.108 or later. RAXE300 firmware 1.0.9.82 or later
A vulnerability exists in the firmware update process of the NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router). This vulnerability stems from improper certificate validation, which allows attackers who can intercept and modify traffic to the device to execute arbitrary commands. Devices with automatic updates enabled may have already applied the necessary patch. For those that have not, users should check the firmware version and update accordingly.
Users can update to RAX30 firmware version 1.0.14.108 or later, or RAXE300 firmware version 1.0.9.82 or later. Instructions for downloading the latest firmware are available on the NETGEAR support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.netgear.com/000070355/NETGEAR-Security-Advisories-November-2025 | Netgear, Inc. | Vendor Advisory |
| https://www.netgear.com/support/product/rax30 | Netgear, Inc. | Product |
| https://www.netgear.com/support/product/raxe300 | Netgear, Inc. | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | Netgear, Inc. |
Affected Products
| Product | Versions |
|---|---|
| netgear rax30 firmware | < 1.0.14.108 |
CPE
Remediation
| |
| netgear rax30 | All versions |
CPE
Remediation
| |
| netgear raxe300 firmware | < 1.0.9.82 |
CPE
Remediation
| |
| netgear raxe300 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Netgear, Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 8, 2025 | Initial Analysis | [email protected] |
| Nov 11, 2025 | New CVE Received | Netgear, Inc. |