Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-12847


NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.


Published

2025-01-10T20:15:30.150

Last Modified

2025-11-20T22:15:53.813

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-78
    CWE-306
  • Type: Primary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear dgn1000_firmware < 1.1.00.48 Yes
Hardware netgear dgn1000 - No

References