PT-2025-23606 · NetGear · Netgear Wnr614
Shuanunio
·
Published
2024-12-10
·
Updated
2025-08-11
·
CVE-2025-5495
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netgear WNR614 version 1.1.0.28 1.0.1WW
Description
A critical issue affects the URL Handler component, allowing for improper authentication. The manipulation of the input
%00currentsetting.htm can lead to this issue. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This issue has been circulating as a 0day since 2024.Recommendations
For Netgear WNR614 version 1.1.0.28 1.0.1WW, consider restricting access to the URL Handler component until a patch is available. Avoid using the input
%00currentsetting.htm in the affected URL Handler to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Wnr614