Junglewise Threat Intelligence

CVE-2025-13799: ADSLR NBR1005GPEV2 command injection in ap_macfilter_del

CVE-2025-13799 · Severity: medium · CVSS 6.3 · Published 2025-12-01

Executive brief

A command injection vulnerability exists in ADSLR NBR1005GPEV2 router firmware in the MAC filter deletion function. An attacker can remotely exploit this flaw by manipulating the MAC address parameter in /send_order.cgi to execute arbitrary system commands, potentially compromising the router's configuration, network traffic, or internal systems.

Technical details

This is a command injection vulnerability in the ap_macfilter_del function of /send_order.cgi on ADSLR NBR1005GPEV2 250814-r037c firmware. The vulnerability exists because user-supplied input in the mac parameter is not properly sanitized before being used in system commands. An unauthenticated remote attacker can send a crafted request to /send_order.cgi with a malicious mac argument containing shell metacharacters to execute arbitrary commands with router privileges. The vulnerability is confirmed exploitable and has been publicly disclosed, though there is no indication that the vendor has provided a patch.

Affected products

  • ADSLR NBR1005GPEV2 250814-r037c

Timeline

  • 2025-12-01: disclosed
  • other: Vendor contacted but did not respond

References

Related threats