← Vulnerability feed

Vulnerability record · CVE-2013-2751 · published 12 December 2013

CVE-2013-2751: NETGEAR ReadyNAS FrontView eval injection allows remote Perl code execution

Netgear · Raidiator

The FrontView web interface in NETGEAR ReadyNAS RAIDiator (before 4.1.12 and 4.2.x before 4.2.24) passes crafted input into a Perl eval in frontview/lib/np_handler.pl, tied to the forgot password workflow. An unauthenticated remote attacker can inject and execute arbitrary Perl code on the device. Because the flaw is reachable over the network with no credentials, it is a full compromise of the NAS.

10.0 CVSS 2.0 High EPSS 72% · top 0.6% CWE-94 · Code injection
10.0CVSS 2.0 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to execute arbitrary Perl code via a crafted request, related to the "forgot password workflow."

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit code, and very high EPSS makes this an urgent patch-or-isolate case.

What it is

The FrontView web interface in NETGEAR ReadyNAS RAIDiator (before 4.1.12 and 4.2.x before 4.2.24) passes crafted input into a Perl eval in frontview/lib/np_handler.pl, tied to the forgot password workflow. An unauthenticated remote attacker can inject and execute arbitrary Perl code on the device. Because the flaw is reachable over the network with no credentials, it is a full compromise of the NAS.

Impact

An attacker gains arbitrary Perl code execution in the context of the FrontView web service, which third-party reporting describes as leading to root access and complete system takeover of the ReadyNAS device.

Attack surface

Reached over the network through the FrontView web interface via a crafted HTTP request to the forgot password workflow. The CVSS vector (AV:N/AC:L/Au:N) and the description indicate no authentication and no user interaction are required.

Exploitation

Public exploit code exists (Exploit-DB 29815 and a Packet Storm advisory), and EPSS is very high at 0.716 (99.4th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented.

What to do

  • Upgrade RAIDiator to 4.1.12 or later, or 4.2.24 or later, per the vendor advisory.
  • If the device cannot be patched, remove FrontView HTTP/HTTPS exposure from untrusted networks and restrict management access to a trusted segment.
  • Disable or block remote access to the FrontView web interface until the upgrade is applied.
  • After patching, review the device for signs of prior compromise and reset administrative credentials.

Detection

  • Inspect FrontView web server logs for suspicious requests to the forgot password workflow containing Perl code or shell metacharacters.
  • Monitor for unexpected child processes spawned by the FrontView web service (perl, sh, or similar) on the ReadyNAS.
  • Alert on outbound connections or new files on the NAS that do not match normal administrative activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2751 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2013-2752Netgear raidiator cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 al…EPSS 1.0%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2013-2751), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.