A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulation of the argument mac can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
| Link | Resource |
|---|---|
| https://vuldb.com/?ctiid.333809 | Permissions Required VDB Entry |
| https://vuldb.com/?id.333809 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.691841 | Third Party Advisory VDB Entry |
| https://www.notion.so/2a60c75766a8805a8973d2ff6a6bcb26 | Exploit Third Party Advisory |
| https://www.notion.so/Report-8-2a60c75766a8805a8973d2ff6a6bcb26 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
11 Dec 2025, 22:44
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:adslr:b-qe2w401:-:*:*:*:*:*:*:* cpe:2.3:o:adslr:b-qe2w401_firmware:*:*:*:*:*:*:*:* |
|
| First Time |
Adslr b-qe2w401
Adslr Adslr b-qe2w401 Firmware |
|
| References | () https://vuldb.com/?ctiid.333809 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.333809 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.691841 - Third Party Advisory, VDB Entry | |
| References | () https://www.notion.so/2a60c75766a8805a8973d2ff6a6bcb26 - Exploit, Third Party Advisory | |
| References | () https://www.notion.so/Report-8-2a60c75766a8805a8973d2ff6a6bcb26 - Exploit, Third Party Advisory |
01 Dec 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Dec 2025, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-01 01:16
Updated : 2025-12-11 22:44
NVD link : CVE-2025-13798
Mitre link : CVE-2025-13798
CVE.ORG link : CVE-2025-13798
JSON object : View
Products Affected
adslr
- b-qe2w401_firmware
- b-qe2w401
