Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5fhc-hfwc-c254

Опубликовано: 01 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 7.2

Описание

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.

EPSS

Процентиль: 98%
0.61009
Средний

9.4 Critical

CVSS4

7.2 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
nvd
6 месяцев назад

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.

CVSS3: 9.1
fstec
около 13 лет назад

Уязвимость сценария pppoe.cgi микропрограммного обеспечения маршрутизаторов Netgear DGN2200B, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 98%
0.61009
Средний

9.4 Critical

CVSS4

7.2 High

CVSS3

Дефекты

CWE-78