NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 10 Jan 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017. | |
Title | NETGEAR DGN setup.cgi OS Command Injection | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-01-10T21:13:27.818Z
Reserved: 2024-12-20T14:49:29.976Z
Link: CVE-2024-12847

Updated: 2025-01-10T21:13:22.332Z

Status : Received
Published: 2025-01-10T20:15:30.150
Modified: 2025-01-10T20:15:30.150
Link: CVE-2024-12847

No data.