CVE-2025-5145: Netcore POWER13 Query String cgi-bin command injection
A vulnerability, which was classified as critical, was found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, NBR200V2 and POWER13 up to 20250508. This affects an unknown part of the file /www/cgi-bin/ of the component Query String Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5145?
CVE-2025-5145 is classified as a critical vulnerability.
How do I fix CVE-2025-5145?
To fix CVE-2025-5145, you should update your affected Netcore device firmware to a version released after May 8, 2025.
What products are affected by CVE-2025-5145?
The affected products include Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, NBR200V2, and POWER13 versions up to 20250508.
What type of vulnerability is CVE-2025-5145?
CVE-2025-5145 is a query string handler vulnerability that allows for manipulation and potential exploitation.
What impact does CVE-2025-5145 have?
The impact of CVE-2025-5145 may include unauthorized access and execution of arbitrary commands.