Netgear Routers setup.cgi RCE
36Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 8.6epss 4.4%
de la publicación al arma0 días
Publicada en NVD1 ago
metasploit6 feb
probabilidad de explotación
4.4%top 9% de las CVE
explotación observada
noninguna fuente lo reporta
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling command injection through crafted POST requests. This flaw enables remote attackers to deploy payloads or manipulate system state post-authentication.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Netgear · DGN1000BReferencias
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/netgear_dgn1000b_setup_exec.rbhttps://web.archive.org/web/20150218074318/http://www.s3cur1ty.de/m1adv2013-005https://www.exploit-db.com/exploits/24464https://www.exploit-db.com/exploits/24931https://www.vulncheck.com/advisories/netgear-legacy-routers-rce-2