VulnerabilityAnalyzed
CVE-2025-13798
Executing manipulation of the argument mac can lead to command injection.
LOW 2.1EPSS 7.10%
Does this matter?
Lower severity and a low EPSS score (7.10%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulation of the argument mac can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 7.10% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-77
- Affected
- adslr/b-qe2w401 firmware
- Source
- cna@vuldb.com
References
- https://vuldb.com/?ctiid.333809Permissions Required, VDB Entry
- https://vuldb.com/?id.333809Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.691841Third Party Advisory, VDB Entry
- https://www.notion.so/2a60c75766a8805a8973d2ff6a6bcb26Exploit, Third Party Advisory
- https://www.notion.so/Report-8-2a60c75766a8805a8973d2ff6a6bcb26Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.