CVE-2025-28219: Command Injection
Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usbadv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28219?
CVE-2025-28219 is considered a critical vulnerability due to its ability to allow arbitrary command execution by remote attackers.
How do I fix CVE-2025-28219?
To mitigate CVE-2025-28219, update the Netgear DC112A to the latest firmware version that addresses this vulnerability.
What is the attack vector for CVE-2025-28219?
CVE-2025-28219 can be exploited by sending crafted POST requests to the usb_adv.cgi endpoint with a malicious parameter 'deviceName'.
What are the potential impacts of CVE-2025-28219 if exploited?
If exploited, CVE-2025-28219 allows attackers to execute arbitrary commands on the Netgear DC112A device, potentially compromising the device and the network it's connected to.
Which devices are affected by CVE-2025-28219?
CVE-2025-28219 specifically affects devices running Netgear DC112A firmware version V1.0.0.64.