First published: Fri Mar 28 2025(Updated: )
Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear DC112A |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-28219 is considered a critical vulnerability due to its ability to allow arbitrary command execution by remote attackers.
To mitigate CVE-2025-28219, update the Netgear DC112A to the latest firmware version that addresses this vulnerability.
CVE-2025-28219 can be exploited by sending crafted POST requests to the usb_adv.cgi endpoint with a malicious parameter 'deviceName'.
If exploited, CVE-2025-28219 allows attackers to execute arbitrary commands on the Netgear DC112A device, potentially compromising the device and the network it's connected to.
CVE-2025-28219 specifically affects devices running Netgear DC112A firmware version V1.0.0.64.