CRITICAL🇵🇱 Wersja polska

CVE-2013-10060

CVSS 9.4v4.0pub. 2025-08-01upd. 2025-09-23

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.

🤖 AI Analysis
How it works

The vulnerability is located in the pppoe.cgi endpoint, where the pppoe_username parameter is not properly filtered before being passed to a system call. An attacker with valid credentials can submit crafted input containing additional system commands that will be executed by the router with operating system privileges. According to the vulnerability description, the effects of exploitation may persist after device restart unless the original configuration is restored.

Impact

An attacker can gain full control of the device by executing arbitrary commands in the router's operating system, which includes modifying configuration, intercepting network traffic, and maintaining persistent access.

Mitigation & patch

Apply patches available from the manufacturer according to the references. If an update is not available, it is recommended to restrict access to the router's administrative interface to trusted IP addresses only and disable remote access to the management panel.

Who is affected

Netgear DGN2200B with firmware version 1.0.0.36 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Netgear Dgn2200b

    HW
    Netgear
    all versions
  • Netgear Dgn2200b Firmware

    OS
    Netgear
    ≤ 1.1.0.36
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2016-11059HIGH7.5same product

Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before...

CVE-2018-21156HIGH7.2same product

Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before ...

CVE-2018-21163HIGH7.2same product

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D...

CVE-2018-21139HIGH7.5same product

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 before 1.0.0.2...

CVE-2017-18756HIGH8.8same product

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6220 befor...