NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 10 Jan 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017. | |
Title | NETGEAR DGN setup.cgi OS Command Injection | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-01-10T19:36:36.675Z
Updated: 2025-01-10T21:13:27.818Z
Reserved: 2024-12-20T14:49:29.976Z
Link: CVE-2024-12847
Vulnrichment
Updated: 2025-01-10T21:13:22.332Z
NVD
Status : Received
Published: 2025-01-10T20:15:30.150
Modified: 2025-01-10T20:15:30.150
Link: CVE-2024-12847
Redhat
No data.