← All CVEs

CVE-2024-12847

critical · 9.8

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.

9.8
CVSS
29.9%
EPSS (exploit prob.)
98th
EPSS percentile
2025-01-10
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78CWE-306

Affected products

VendorProductAffected versions
netgeardgn1000_firmware< 1.1.00.48
netgeardgn1000all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-12847