CVE detail
CVE-2025-5495
A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknown part of the component URL Handler. The manipulation with the input %00currentsetting.htm leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This issue appears to have been circulating as an 0day since 2024.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.netgear.com/www.netgear.com
No excerpt available.
Vendor Advisorywww.netgear.comJun 3, 2025, 1:15 PM - https://vuldb.com/?submit.584939vuldb.com
No excerpt available.
Exploitvuldb.comJun 3, 2025, 1:15 PM - https://vuldb.com/?id.310911vuldb.com
No excerpt available.
Exploitvuldb.comJun 3, 2025, 1:15 PM - https://vuldb.com/?ctiid.310911vuldb.com
No excerpt available.
Exploitvuldb.comJun 3, 2025, 1:15 PM No excerpt available.
Exploitgithub.comJun 3, 2025, 1:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- Shuanunio/CVE_RequestsHigh confidencegithubNVD Exploit reference0 starsDiscovered Aug 10, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-11057CVSS 7.5 · High
Certain NETGEAR devices are affected by mishandling of repeated URL calls. This affects JNR1010v2 before 2017-01-06, WNR614 before 2017-01-06, WNR618 before 2017-01-06, JWNR2000v5…
- CVE-2024-36792CVSS 8.2 · High
An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.
- CVE-2024-36790CVSS 8.8 · High
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
- CVE-2024-36789CVSS 8.1 · High
An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.
- CVE-2024-36788CVSS 4.8 · Medium
Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications…
- CVE-2024-36787CVSS 8.8 · High
An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.