Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-10060


An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.


Published

2025-08-01T21:15:28.163

Last Modified

2025-09-23T17:07:29.847

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear dgn2200b_firmware ≤ 1.1.0.36 Yes
Hardware netgear dgn2200b - No

References