Vulnerability record · CVE-2013-2751 · published 12 December 2013
CVE-2013-2751: NETGEAR ReadyNAS FrontView eval injection allows remote Perl code execution
Netgear · Raidiator
The FrontView web interface in NETGEAR ReadyNAS RAIDiator (before 4.1.12 and 4.2.x before 4.2.24) passes crafted input into a Perl eval in frontview/lib/np_handler.pl, tied to the forgot password workflow. An unauthenticated remote attacker can inject and execute arbitrary Perl code on the device. Because the flaw is reachable over the network with no credentials, it is a full compromise of the NAS.
Description
Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to execute arbitrary Perl code via a crafted request, related to the "forgot password workflow."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit code, and very high EPSS makes this an urgent patch-or-isolate case.
What it is
The FrontView web interface in NETGEAR ReadyNAS RAIDiator (before 4.1.12 and 4.2.x before 4.2.24) passes crafted input into a Perl eval in frontview/lib/np_handler.pl, tied to the forgot password workflow. An unauthenticated remote attacker can inject and execute arbitrary Perl code on the device. Because the flaw is reachable over the network with no credentials, it is a full compromise of the NAS.
Impact
An attacker gains arbitrary Perl code execution in the context of the FrontView web service, which third-party reporting describes as leading to root access and complete system takeover of the ReadyNAS device.
Attack surface
Reached over the network through the FrontView web interface via a crafted HTTP request to the forgot password workflow. The CVSS vector (AV:N/AC:L/Au:N) and the description indicate no authentication and no user interaction are required.
Exploitation
Public exploit code exists (Exploit-DB 29815 and a Packet Storm advisory), and EPSS is very high at 0.716 (99.4th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented.
What to do
- Upgrade RAIDiator to 4.1.12 or later, or 4.2.24 or later, per the vendor advisory.
- If the device cannot be patched, remove FrontView HTTP/HTTPS exposure from untrusted networks and restrict management access to a trusted segment.
- Disable or block remote access to the FrontView web interface until the upgrade is applied.
- After patching, review the device for signs of prior compromise and reset administrative credentials.
Detection
- Inspect FrontView web server logs for suspicious requests to the forgot password workflow containing Perl code or shell metacharacters.
- Monitor for unexpected child processes spawned by the FrontView web service (perl, sh, or similar) on the ReadyNAS.
- Alert on outbound connections or new files on the NAS that do not match normal administrative activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2751 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2751), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.