Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-7266 | An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling command injection through crafted POST requests. This flaw enables remote attackers to deploy payloads or manipulate system state post-authentication. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 21 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear dgn1000v3 Firmware
|
|
| CPEs | cpe:2.3:o:netgear:dgn1000v3_firmware:1.0.0.25:*:*:*:*:*:*:* cpe:2.3:o:netgear:dgn1000v3_firmware:1.0.0.45:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgear dgn1000v3 Firmware
|
Tue, 23 Sep 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear dgn1000b
Netgear dgn1000b Firmware |
|
| CPEs | cpe:2.3:h:netgear:dgn1000b:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:dgn1000b_firmware:1.1.00.24:*:*:*:*:*:*:* cpe:2.3:o:netgear:dgn1000b_firmware:1.1.00.45:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgear dgn1000b
Netgear dgn1000b Firmware |
|
| Metrics |
cvssV3_1
|
Wed, 06 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear
Netgear dgn1000 |
|
| Vendors & Products |
Netgear
Netgear dgn1000 |
Fri, 01 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling command injection through crafted POST requests. This flaw enables remote attackers to deploy payloads or manipulate system state post-authentication. | |
| Title | Netgear Routers setup.cgi RCE | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-21T00:16:28.258Z
Reserved: 2025-08-01T18:31:18.857Z
Link: CVE-2013-10061
Updated: 2025-08-06T14:15:52.230Z
Status : Analyzed
Published: 2025-08-01T21:15:28.350
Modified: 2025-09-23T23:30:15.463
Link: CVE-2013-10061
No data.
OpenCVE Enrichment
Updated: 2025-08-05T11:39:02Z
EUVD