Command Injection Vulnerability in Netcore Networking Devices
CVE-2025-5145
What is CVE-2025-5145?
A command injection vulnerability has been identified in multiple Netcore networking devices, affecting various models including the NBR1005GPEV2 and POWER13. This issue arises from improper handling of input in the Query String Handler component located in /www/cgi-bin/. An attacker can exploit this vulnerability remotely, allowing unauthorized command execution on the affected devices. With the exploit publicly disclosed, it is crucial for users to assess their security measures and update their systems promptly to mitigate potential risks.
Affected Version(s)
B6V2 20250508
COVER5 20250508
NAP830 20250508
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved