CVE-2025-45493: Command Injection
Published Dec 23, 2025
·Updated
Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the actionbandwidth function.
Affected Software
3 affected components
Netgear EX8000
All of the following
Netgear Ex8000 Firmware=1.0.0.126
Netgear EX8000
Event History
Dec 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-45493?
CVE-2025-45493 has been classified as a high severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2025-45493?
To fix CVE-2025-45493, ensure that you update the Netgear EX8000 firmware to the latest version released by the vendor.
3
What type of vulnerability is CVE-2025-45493?
CVE-2025-45493 is categorized as a command injection vulnerability affecting the action_bandwidth function.
4
What are the potential impacts of CVE-2025-45493?
The potential impacts of CVE-2025-45493 include unauthorized access and control over the device, enabling malicious commands to be executed.
5
Is my device affected by CVE-2025-45493?
If you are using the Netgear EX8000 with firmware version V1.0.0.126 or earlier, your device is affected by CVE-2025-45493.