Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq8m-gwqp-g9xv

Опубликовано: 10 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been exploited in the wild since at least 2017.

EPSS

Процентиль: 99%
0.67076
Средний

9.8 Critical

CVSS3

Дефекты

CWE-288
CWE-306
CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.

CVSS3: 9.8
fstec
около 1 года назад

Уязвимость встроенного программного обеспечения маршрутизатора NETGEAR DGN1000, связанная с обходом процедуры аутентификации посредством использования альтернативного пути или канала, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.67076
Средний

9.8 Critical

CVSS3

Дефекты

CWE-288
CWE-306
CWE-78