Executive brief
A command injection vulnerability exists in ADSLR NBR1005GPEV2 router firmware in the MAC filter deletion function. An attacker can remotely exploit this flaw by manipulating the MAC address parameter in /send_order.cgi to execute arbitrary system commands, potentially compromising the router's configuration, network traffic, or internal systems.
Technical details
This is a command injection vulnerability in the ap_macfilter_del function of /send_order.cgi on ADSLR NBR1005GPEV2 250814-r037c firmware. The vulnerability exists because user-supplied input in the mac parameter is not properly sanitized before being used in system commands. An unauthenticated remote attacker can send a crafted request to /send_order.cgi with a malicious mac argument containing shell metacharacters to execute arbitrary commands with router privileges. The vulnerability is confirmed exploitable and has been publicly disclosed, though there is no indication that the vendor has provided a patch.
Affected products
- ADSLR NBR1005GPEV2 250814-r037c
Timeline
- 2025-12-01: disclosed
- other: Vendor contacted but did not respond