CVE-2025-13799 is a critical command injection vulnerability affecting ADSLR NBR1005GPEV2 250814-r037c firmware, specifically within the ap_macfilter_del function of the /send_order.cgi file, and also impacting adslr b_qe2w401 products. This vulnerability allows for remote command injection through manipulation of the 'mac' argument. With a CVSS score of 9.8 (CRITICAL), it poses a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While the exploit has been publicly disclosed and the vendor has not responded, there is no evidence of active exploitation, nor are there Metasploit, Nuclei, or ExploitDB modules available, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 250814-r037cCPE matchmatch criteria | cpe:2.3:o:adslr:b-qe2w401_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.