PT-2025-48401 · Unknown · Adslr Nbr1005Gpev2

2Er00Ne

·

Published

2025-12-01

·

Updated

2025-12-26

·

CVE-2025-13798

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ADSLR NBR1005GPEV2 version 250814-r037c
Description A flaw exists in ADSLR NBR1005GPEV2 250814-r037c. The issue is related to the ap macfilter add function within the /send order.cgi file. Manipulation of the mac argument can result in command injection. This attack can be carried out remotely. An exploit for this issue has been published. The vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13798

Affected Products

Adslr Nbr1005Gpev2