---
id: CVE-2025-13799
title: A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c
summary: >-
  A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This
  vulnerability affects the function ap_macfilter_del of the file
  /send_order.cgi. The manipulation of the argument mac leads to command
  injection. It is possible to i…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-77
  - CWE-77
vendor: adslr
product: b-qe2w401_firmware
affected:
  - b-qe2w401_firmware <= 250814-r037c
published: '2025-12-01'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13799'
references:
  - url: 'https://vuldb.com/?ctiid.333810'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.333810'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.691842'
    label: cna@vuldb.com
  - url: 'https://www.notion.so/2a60c75766a8801e8e4bdd3be8072d9d'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.09438
epssPercentile: 0.95197
ingestedAt: '2026-09-03T03:55:22.889Z'
---

## Overview

A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.cgi. The manipulation of the argument mac leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `b-qe2w401_firmware <= 250814-r037c`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
