CVE-2025-12943General(netgear / rax30)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch netgear rax30 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device. Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update to the latest. Fixed in: RAX30 firmware 1.0.14.108 or later. RAXE300 firmware 1.0.9.82 or later

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rax30
  • rax30_firmware
  • raxe300
  • raxe300_firmware

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • PoC: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
rax30rax30_firmwareraxe300raxe300_firmware

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 103-2503-27
Signal classification2 categories
General
266.7%
PoC
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-252
General2
2026-03-271
PoC1
Full discourse3 posts
  • Jake Swiz@JakeSwiz80263
    PoC

    It's here. Full video just went live. I weaponized CVE-2025-12943 on the @NETGEAR Nighthawk RAXE300, no public PoC existed so I built the entire chain from scratch. Stop sleeping on N-days. https://www.youtube.com/watch?v=jQAMoChqX3o #cybersecurity #hacking #infosec

    Post summary

    The user demonstrates building an exploit chain for CVE‑2025‑12943 in a YouTube video, showing how the vulnerability can be weaponized despite the absence of a public PoC.

    00000183
    6 followersView on X
  • Jake Swiz@JakeSwiz80263
    General

    I literally could not believe what I was looking at The entire firmware update system uses curl --insecure That means the router will accept ANY certificate from ANYONE. Your @NETGEAR Nighthawk RAXE300 just... trusts whatever it connects to CVE-2025-12943 // @CISAgov #CVE

    Post summary

    The tweet highlights that the NETGEAR Nighthawk RAXE300 firmware update system uses curl with the --insecure flag, causing the device to accept any HTTPS certificate, which could expose it to man‑in‑the‑middle attacks. No proof of concept, exploit, patch, or active exploitation details are provided.

    00000158
    3 followersView on X
  • Jake Swiz@JakeSwiz80263
    General

    CVE-2025-12943 -- as of 03/25/2026, no PUBLIC proof-of-concept (PoC) exploit exists. I decided to challenge myself and change that. Okay so I pulled the old firmware and the patched firmware off Netgear's site, extracted both, loaded them into Ghidra, and started diffing them!

    Post summary

    The user acknowledges CVE‑2025‑12943 with no public PoC yet, notes a patched firmware exists, and is analysing firmware to potentially develop a PoC, but no PoC or exploit is provided.

    00000323
    3 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWnetgearrax30---
OSnetgearrax30_firmware---
HWnetgearraxe300---
OSnetgearraxe300_firmware---

Explore more