CVE-2025-7407 — Command Injection in Netgear D6400
Severity
5.3MEDIUMNVD
EPSS
1.3%
top 20.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 10
Latest updateJan 26
Description
A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of the file diag.cgi. The manipulation of the argument host_name leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early and confirmed the existence of the vulnerability. They reacted very quickly, professional and kind. This vulnerability only affects products that…
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected Packages2 packages
🔴Vulnerability Details
3🔍Detection Rules
1Suricata▶
ET WEB_SPECIFIC_APPS Netgear diag.cgi host_name Parameter Command Injection Attempt (CVE-2025-7407)↗2026-01-26