PT-2025-31695 · NetGear · Netgear Routers

Published

2012-10-15

·

Updated

2025-09-23

·

CVE-2013-10061

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netgear routers versions 1.1.00.24 through 1.1.00.45
Description An authenticated OS command injection vulnerability exists due to improper input neutralization. This allows for command injection through crafted POST requests to the /setup.cgi API endpoint via the TimeToLive parameter. Successful exploitation enables remote attackers to deploy payloads or manipulate system state after authentication.
Recommendations For Netgear routers versions 1.1.00.24 through 1.1.00.45, restrict access to the setup.cgi endpoint or sanitize the TimeToLive parameter to prevent command injection.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-09548
CVE-2013-10061

Affected Products

Netgear Routers