---
id: CVE-2025-13800
title: A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c
summary: >-
  A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue
  affects the function set_mesh_disconnect of the file /send_order.cgi. The
  manipulation of the argument mac results in command injection. It is possible
  to launch th…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-77
vendor: adslr
product: b-qe2w401_firmware
affected:
  - b-qe2w401_firmware <= 250814-r037c
published: '2025-12-01'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13800'
references:
  - url: 'https://vuldb.com/?ctiid.333811'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.333811'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.691942'
    label: cna@vuldb.com
  - url: 'https://www.notion.so/2a70c75766a88023aa0ed833ff0239e1'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.09438
epssPercentile: 0.95254
ingestedAt: '2026-09-03T03:55:22.931Z'
---

## Overview

A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `b-qe2w401_firmware <= 250814-r037c`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
