← Back to browse · API

CVE-2025-28219

Severity
CRITICAL
CVSS
9.8
EPSS
0.11622
Risk score
43.27
CISA KEV
No
PoC
No
Published
2025-03-28
Modified
2025-04-21
First seen
2026-08-07
Aliases
EUVD-2025-8622, GHSA-F45W-55JR-PVP2
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-8622

Description

Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.

References