NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.
History

Thu, 25 Sep 2025 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288

Thu, 25 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
CWE-78

Fri, 10 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jan 2025 19:45:00 +0000

Type Values Removed Values Added
Description NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.
Title NETGEAR DGN setup.cgi OS Command Injection
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-09-25T18:23:12.535Z

Reserved: 2024-12-20T14:49:29.976Z

Link: CVE-2024-12847

cve-icon Vulnrichment

Updated: 2025-01-10T21:13:22.332Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-10T20:15:30.150

Modified: 2025-09-25T19:15:40.653

Link: CVE-2024-12847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:09:38Z