NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.
History

Fri, 10 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jan 2025 19:45:00 +0000

Type Values Removed Values Added
Description NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.
Title NETGEAR DGN setup.cgi OS Command Injection
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-01-10T19:36:36.675Z

Updated: 2025-01-10T21:13:27.818Z

Reserved: 2024-12-20T14:49:29.976Z

Link: CVE-2024-12847

cve-icon Vulnrichment

Updated: 2025-01-10T21:13:22.332Z

cve-icon NVD

Status : Received

Published: 2025-01-10T20:15:30.150

Modified: 2025-01-10T20:15:30.150

Link: CVE-2024-12847

cve-icon Redhat

No data.