NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an...
Critical severity
Unreviewed
Published
Jan 10, 2025
to the GitHub Advisory Database
•
Updated Jan 10, 2025
Description
Published by the National Vulnerability Database
Jan 10, 2025
Published to the GitHub Advisory Database
Jan 10, 2025
Last updated
Jan 10, 2025
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.
References