PT-2025-29093 · NetGear · Netgear R6400

Bond

·

Published

2025-07-02

·

Updated

2025-07-15

·

CVE-2025-7407

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Netgear D6400 version 1.0.0.114
Description: A critical vulnerability exists in the diag.cgi file of the Netgear D6400. Manipulation of the host name argument can lead to os command injection. This issue is remotely exploitable. The exploit has been publicly disclosed. This vulnerability affects products that are no longer supported by the maintainer.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-09960
CVE-2025-7407

Affected Products

Netgear R6400