ADSLR NBR1005GPEV2 Command Injection Vulnerability in Mesh Disconnect Function
Vulnerability
A command injection vulnerability has been identified in the ADSL NBR1005GPEV2 router, specifically in the 250814-r037c version. The issue arises in the 'set_mesh_disconnect' function within the '/send_order.cgi' file. This vulnerability allows remote attackers to execute arbitrary commands by manipulating the 'mac' argument, as the application improperly sanitizes input before incorporating it into command executions. The vulnerability has been publicly disclosed and is actively exploitable.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the affected device, with potential consequences for the device's confidentiality, integrity, and availability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
