CVE-2024-12847 Details
Description
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.
An authentication bypass vulnerability has been identified in the Netgear DGN1000 router, affecting firmware versions prior to 1.1.00.48, as well as the DGN2200 v1 model. This vulnerability allows remote, unauthenticated attackers to execute arbitrary operating system commands with root privileges by sending crafted HTTP requests to the setup.cgi endpoint. The embedded web server bypasses authentication checks for certain URLs, enabling exploitation. This vulnerability has been actively exploited since 2017.
Users of the Netgear DGN1000 router should upgrade to firmware version 1.1.00.48. Netgear DGN2200 v1 is no longer supported, but versions v3 and v4 should not be affected by this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://seclists.org/bugtraq/2013/Jun/8 | [email protected] | Mailing ListThird Party Advisory |
| https://vulncheck.com/advisories/netgear-dgn | [email protected] | Vendor Advisory |
| https://www.exploit-db.com/exploits/25978 | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43055 | [email protected] | ExploitVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| netgear dgn1000 firmware | < 1.1.00.48 |
CPE
Remediation
| |
| netgear dgn1000 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Dec 19, 2025 | CVE Modified | [email protected] |
| Nov 20, 2025 | CVE Modified | [email protected] |
| Nov 20, 2025 | Initial Analysis | [email protected] |
| Sep 25, 2025 | CVE Modified | [email protected] |
| Jan 10, 2025 | New CVE Received | [email protected] |