Junglewise Threat Intelligence

CVE-2025-13797: ADSLR B-QE2W401 command injection in /send_order.cgi

CVE-2025-13797 · Severity: medium · CVSS 6.3 · Published 2025-12-01

Executive brief

The ADSLR B-QE2W401 is a router device used for broadband connectivity in home and office networks. A command injection vulnerability in the web management interface allows attackers to remotely execute arbitrary system commands by manipulating the del_swifimac parameter, potentially compromising network security and enabling unauthorized access to the device.

Technical details

The vulnerability is a command injection flaw in the parameterdel_swifimac function within /send_order.cgi. An attacker can exploit this by crafting a malicious request with specially crafted input in the del_swifimac parameter, allowing arbitrary command execution on the device without requiring authentication. The attack is network-accessible and exploits insufficient input validation. An attacker can achieve remote code execution with the privileges of the web server, potentially leading to full device compromise, credential theft, or network-level attacks.

Affected products

  • ADSLR B-QE2W401 250814-r037c

Timeline

  • 2025-12-01: disclosed: Publicly disclosed; exploit now available

References

Related threats