---
id: CVE-2025-13797
title: A vulnerability was detected in ADSLR B-QE2W401 250814-r037c
summary: >-
  A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this
  issue is the function parameterdel_swifimac of the file /send_order.cgi.
  Performing manipulation of the argument del_swifimac results in command
  injection. Th…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-77
  - CWE-77
vendor: adslr
product: b-qe2w401_firmware
affected:
  - b-qe2w401_firmware <= 250814-r037c
published: '2025-12-01'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13797'
references:
  - url: 'https://vuldb.com/?ctiid.333808'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.333808'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.691838'
    label: cna@vuldb.com
  - url: 'https://www.notion.so/2a60c75766a88027a6aec07b378332a8'
    label: cna@vuldb.com
  - url: 'https://www.notion.so/report-7-2a60c75766a88027a6aec07b378332a8'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.07099
epssPercentile: 0.94002
ingestedAt: '2026-09-03T03:55:22.847Z'
---

## Overview

A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cgi. Performing manipulation of the argument del_swifimac results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `b-qe2w401_firmware <= 250814-r037c`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
