Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 06 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 05 Aug 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Netgear
Netgear dgn1000 |
|
Vendors & Products |
Netgear
Netgear dgn1000 |
Fri, 01 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling command injection through crafted POST requests. This flaw enables remote attackers to deploy payloads or manipulate system state post-authentication. | |
Title | Netgear Routers setup.cgi RCE | |
Weaknesses | CWE-78 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-08-06T14:16:02.991Z
Reserved: 2025-08-01T18:31:18.857Z
Link: CVE-2013-10061

Updated: 2025-08-06T14:15:52.230Z

Status : Awaiting Analysis
Published: 2025-08-01T21:15:28.350
Modified: 2025-08-06T15:15:30.880
Link: CVE-2013-10061

No data.

Updated: 2025-08-05T11:39:02Z