CVE-2024-12847 is a critical authentication bypass vulnerability affecting NETGEAR DGN1000 routers prior to firmware version 1.1.00.48. This flaw allows a remote, unauthenticated attacker to execute arbitrary operating system commands as root by sending specially crafted HTTP requests to the setup.cgi endpoint. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. The vulnerability has been actively exploited in the wild since at least 2017, with public exploit modules available (e.g., Metasploit), and is currently attracting significant community discussion and media coverage, indicating ongoing threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 1.1.00.48CPE match | cpe:2.3:h:netgear:dgn1000:*:*:*:*:*:*:*:* | ||
< 1.1.00.48CPE matchmatch criteria | cpe:2.3:o:netgear:dgn1000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.