CVE-2025-7407: Netgear D6400 diag.cgi os command injection
A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of the file diag.cgi. The manipulation of the argument hostname leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early and confirmed the existence of the vulnerability. They reacted very quickly, professional and kind. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7407?
CVE-2025-7407 is classified as a critical vulnerability due to the potential for remote os command injection.
How do I fix CVE-2025-7407?
To fix CVE-2025-7407, update the Netgear D6400 to the latest firmware version provided by Netgear.
What software is affected by CVE-2025-7407?
CVE-2025-7407 affects the Netgear D6400 router running version 1.0.0.114.
Can CVE-2025-7407 be exploited remotely?
Yes, CVE-2025-7407 can be exploited remotely, allowing attackers to inject commands via the diag.cgi file.
What impact does CVE-2025-7407 have on users?
CVE-2025-7407 can lead to unauthorized access and control over the affected device, compromising user security.