CVE-2025-25246: Code Injection
Published Feb 5, 2025
·Updated
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
Affected Software
3 affected components
Netgear XR1000<1.0.0.74
Netgear XR1000v2<1.1.0.22
Netgear XR500<2.3.2.134
Event History
Feb 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-25246?
CVE-2025-25246 is considered a critical vulnerability due to its potential for remote code execution by unauthenticated users.
2
How do I fix CVE-2025-25246?
To fix CVE-2025-25246, update your NETGEAR XR1000, XR1000v2, or XR500 device to the latest firmware version available.
3
Which devices are affected by CVE-2025-25246?
CVE-2025-25246 affects NETGEAR XR1000 before version 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134.
4
Can CVE-2025-25246 be exploited remotely?
Yes, CVE-2025-25246 allows remote code execution by unauthenticated users, making it exploitable over the internet.
5
What should I do if I'm using an affected NETGEAR device with CVE-2025-25246?
If you are using an affected NETGEAR device, it is crucial to apply the security patch as soon as possible to mitigate the risk.