ADSLR NBR1005GPEV2 Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in the ADSLNBR1005GPEV2 router, specifically in the 250814-r037c version. The issue arises in the 'ap_macfilter_add' function within the '/send_order.cgi' file. This vulnerability allows remote attackers to execute arbitrary commands by manipulating the 'mac' argument, as the application improperly sanitizes input before incorporating it into command executions.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device, with the executed commands running in the context of the device's operating system.

Reproduction

To reproduce this vulnerability, send a request to the '/send_order.cgi' endpoint with a crafted 'mac' argument. The lack of input validation will enable the injection of command separators, allowing for the execution of arbitrary commands on the device.

Added: Dec 1, 2025, 1:19 AM
Updated: Dec 1, 2025, 1:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
1.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.