CVE-2024-12847
NETGEAR DGN setup.cgi OS Command Injection
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 20, 2024
- Published Date
- January 10, 2025
- Last Updated
- January 10, 2025
- Vendor
- NETGEAR
- Product
- DGN1000
- Description
- NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.
- Tags
- Exploitation
- poc
- Automatable
- Yes
- Technical Impact
- total
- Exploited in the Wild
- Yes (2025-01-10 19:36:36 UTC) Source
edge
CVSS Scores
CVSS v3.1
9.8 - CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
Exploit Status
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CVE | 2025-01-10 19:36:36 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel