Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51148 | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 20 Nov 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017. | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC. |
Thu, 20 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear dgn1000 Firmware
|
|
| CPEs | cpe:2.3:h:netgear:dgn1000:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:dgn1000_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgear dgn1000 Firmware
|
Thu, 25 Sep 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-288 |
Thu, 25 Sep 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 CWE-78 |
Fri, 10 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Jan 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017. | |
| Title | NETGEAR DGN setup.cgi OS Command Injection | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-22T12:23:43.932Z
Reserved: 2024-12-20T14:49:29.976Z
Link: CVE-2024-12847
Updated: 2025-01-10T21:13:22.332Z
Status : Modified
Published: 2025-01-10T20:15:30.150
Modified: 2025-11-20T22:15:53.813
Link: CVE-2024-12847
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:09:38Z
EUVD