Executive brief
The ADSLR B-QE2W401 is a router device used for broadband connectivity in home and office networks. A command injection vulnerability in the web management interface allows attackers to remotely execute arbitrary system commands by manipulating the del_swifimac parameter, potentially compromising network security and enabling unauthorized access to the device.
Technical details
The vulnerability is a command injection flaw in the parameterdel_swifimac function within /send_order.cgi. An attacker can exploit this by crafting a malicious request with specially crafted input in the del_swifimac parameter, allowing arbitrary command execution on the device without requiring authentication. The attack is network-accessible and exploits insufficient input validation. An attacker can achieve remote code execution with the privileges of the web server, potentially leading to full device compromise, credential theft, or network-level attacks.
Affected products
- ADSLR B-QE2W401 250814-r037c
Timeline
- 2025-12-01: disclosed: Publicly disclosed; exploit now available