CRITICAL🇵🇱 Wersja polska

CVE-2025-28219

CVSS 9.8v3.1pub. 2025-03-28upd. 2025-05-02

Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.

🤖 AI Analysis
How it works

The vulnerability results from insufficient validation and sanitization of the 'deviceName' parameter passed to the usb_adv.cgi script via an HTTP POST request. An attacker can inject arbitrary operating system commands into this parameter value, which are then executed by the device with its privileges. The attack requires no authentication or user interaction, and the attack vector scope is network-based.

Impact

An attacker can gain full control over the device by remotely executing arbitrary system commands, which may lead to a breach of confidentiality, integrity, and availability of the device and data processed by it.

Mitigation & patch

Apply patches available from the manufacturer according to the references. If an update is not available, it is recommended to restrict access to the device management interface only to trusted hosts through network segmentation or firewall, and to disable unused USB functions.

Who is affected

Netgear DC112A with firmware version V1.0.0.64

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Netgear Dc112a

    HW
    Netgear
    all versions
  • Netgear Dc112a Firmware

    OS
    Netgear
    1.0.0.64
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2021-45638CRITICAL9.6PL ✓same product

NETGEAR: Pre-Authentication Stack-Based Buffer Overflow w firmware routerów

CVE-2021-45610CRITICAL9.6PL ✓same product

Pre-authentication buffer overflow w urządzeniach NETGEAR (CVE-2021-45610)

CVE-2021-45611CRITICAL9.6PL ✓same product

Buffer overflow bez uwierzytelnienia w routerach NETGEAR

CVE-2021-45527CRITICAL9.6PL ✓same product

Buffer overflow po uwierzytelnieniu w urządzeniach NETGEAR (wiele modeli)

CVE-2021-38516CRITICAL10.0PL ✓same product

Brak kontroli dostępu na poziomie funkcji w urządzeniach NETGEAR