PT-2025-31694 · NetGear · Netgear Routers

Published

2012-12-17

·

Updated

2025-09-23

·

CVE-2013-10060

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netgear routers versions prior to 1.0.0.36
Description An authenticated OS command injection vulnerability exists in Netgear routers. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the ppoe username parameter through the /ppoe.cgi endpoint. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.
Recommendations Update to a version newer than 1.0.0.36.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-09494
CVE-2013-10060

Affected Products

Netgear Routers