CVE-2025-5146: Netcore NBR200V2 HTTP Header routerd passwd_set command injection
A vulnerability has been found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2 and NBR200V2 up to 20250508 and classified as critical. This vulnerability affects the function passwdset of the file /usr/bin/routerd of the component HTTP Header Handler. The manipulation of the argument pwd leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5146?
CVE-2025-5146 is classified as a critical vulnerability.
What products are affected by CVE-2025-5146?
CVE-2025-5146 affects Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, and NBR200V2 up to version 20250508.
How do I fix CVE-2025-5146?
To fix CVE-2025-5146, update the affected Netcore products to a version released after May 8, 2025.
What component is impacted by CVE-2025-5146?
CVE-2025-5146 impacts the function passwd_set in the routerd file of the HTTP Header Handler component.
What kind of vulnerability is CVE-2025-5146?
CVE-2025-5146 is a manipulation vulnerability that can compromise the affected devices' security.