PT-2025-31695 · NetGear · Netgear Routers
Published
2012-10-15
·
Updated
2025-09-23
·
CVE-2013-10061
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Netgear routers versions 1.1.00.24 through 1.1.00.45
Description
An authenticated OS command injection vulnerability exists due to improper input neutralization. This allows for command injection through crafted POST requests to the
/setup.cgi API endpoint via the TimeToLive parameter. Successful exploitation enables remote attackers to deploy payloads or manipulate system state after authentication.Recommendations
For Netgear routers versions 1.1.00.24 through 1.1.00.45, restrict access to the
setup.cgi endpoint or sanitize the TimeToLive parameter to prevent command injection.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Routers