Command Injection Vulnerability in Netcore Router Products
CVE-2025-5146
What is CVE-2025-5146?
A recently discovered command injection vulnerability affects several Netcore router models through the passwd_set function in the /usr/bin/routerd file. Attackers can exploit this weakness by manipulating the 'pwd' argument, allowing for remote command execution. Given that this vulnerability has been publicly disclosed, it poses a significant risk for users of the affected products, warranting immediate attention and potential remediation measures.
Affected Version(s)
B6V2 20250508
COVER5 20250508
NAP830 20250508
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved