An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling command injection through crafted POST requests. This flaw enables remote attackers to deploy payloads or manipulate system state post-authentication.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Aug 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Netgear
Netgear dgn1000 |
|
Vendors & Products |
Netgear
Netgear dgn1000 |
Fri, 01 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling command injection through crafted POST requests. This flaw enables remote attackers to deploy payloads or manipulate system state post-authentication. | |
Title | Netgear Routers setup.cgi RCE | |
Weaknesses | CWE-78 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-01T20:45:34.559Z
Updated: 2025-08-01T20:45:34.559Z
Reserved: 2025-08-01T18:31:18.857Z
Link: CVE-2013-10061

No data.

Status : Awaiting Analysis
Published: 2025-08-01T21:15:28.350
Modified: 2025-08-04T15:06:15.833
Link: CVE-2013-10061

No data.