I
mproper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform MiTM attacks and control over DNS Server to perform command execution.This issue affects R6260: through 1.1.0.86; R6850: through 1.1.0.86.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070355/NETGEAR-Security-Advisories-November-2025 | Vendor Advisory |
| https://www.netgear.com/support/product/r6260 | Product |
| https://www.netgear.com/support/product/r6850 | Product |
Configurations
History
08 Dec 2025, 14:26
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:netgear:r6850_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6850:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6260_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6260:-:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Netgear
Netgear r6850 Firmware Netgear r6850 Netgear r6260 Firmware Netgear r6260 |
|
| References | () https://kb.netgear.com/000070355/NETGEAR-Security-Advisories-November-2025 - Vendor Advisory | |
| References | () https://www.netgear.com/support/product/r6260 - Product | |
| References | () https://www.netgear.com/support/product/r6850 - Product |
11 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-11 17:15
Updated : 2025-12-08 14:26
NVD link : CVE-2025-12942
Mitre link : CVE-2025-12942
CVE.ORG link : CVE-2025-12942
JSON object : View
Products Affected
CWE
CWE-20
Improper Input Validation