PT-2025-1029 · NetGear · Netgear Dgn1000

Mumbai

+1

·

Published

2025-01-10

·

Updated

2026-02-25

·

CVE-2024-12847

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NETGEAR DGN1000 versions prior to 1.1.00.48
Description The NETGEAR DGN1000 router contains a flaw that allows bypassing the authentication process through the use of an alternative path or channel. Exploitation of this issue enables a remote, unauthenticated attacker to execute arbitrary operating system commands as root by sending specially crafted HTTP requests to the setup.cgi API Endpoint. This vulnerability has been actively exploited in the wild since at least 2017, including observed activity by the Shadowserver Foundation on 2025-02-06 UTC. The vulnerability allows attackers to interact with the router’s backend services without credentials by utilizing URLs containing the “currentsetting.htm” substring.
Recommendations For NETGEAR DGN1000 versions prior to 1.1.00.48, update the firmware to version 1.1.00.48 or later.

Exploit

Fix

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-00227
CVE-2024-12847

Affected Products

Netgear Dgn1000