Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-12943— Improper certificate validation in firmware update logic in NETGEAR RAX30 and RAXE300

EPSS 0.02% · P5
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-12943

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper certificate validation in firmware update logic in NETGEAR RAX30 and RAXE300
Source: NVD (National Vulnerability Database)
Vulnerability Description
Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device. Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update to the latest. Fixed in: RAX30 firmware 1.0.14.108 or later. RAXE300 firmware 1.0.9.82 or later
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
证书验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
NETGEAR RAX30和NETGEAR RAXE300 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NETGEAR RAX30和NETGEAR RAXE300都是美国网件(NETGEAR)公司的产品。NETGEAR RAX30是一个双频无线路由器。NETGEAR RAXE300是一款无线路由器。 NETGEAR RAX30和RAXE300存在安全漏洞,该漏洞源于固件更新逻辑中的证书验证不当,可能导致拦截和篡改流量的攻击者在设备上执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
NETGEARRAX30 0 ~ 1.0.10.95 -
NETGEARRAXE300 0 ~ 1.0.9.82 -

II. Public POCs for CVE-2025-12943

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-12943

登录查看更多情报信息。

Same Patch Batch · NETGEAR · 2025-11-11 · 4 CVEs total

CVE-2025-12940Credentials recorded in logs in NETGEAR WAX610 and WAX610Y
CVE-2025-12944Improper input validation in NETGEAR DGN2200v4
CVE-2025-12942Improper input validation in NETGEAR R6260 and R6850

IV. Related Vulnerabilities

V. Comments for CVE-2025-12943

No comments yet


Leave a comment