CVE-2013-10060 is an authenticated OS command injection vulnerability affecting Netgear DGN2200B routers with firmware versions 1.0.0.36 and prior, specifically through the pppoe.cgi endpoint. This flaw allows a remote attacker with valid credentials to execute arbitrary commands, potentially leading to full device compromise that can persist across reboots. Rated with a CVSS score of 7.2 (High), the attack requires high privileges but has low attack complexity and no user interaction, resulting in high impact to confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, a Metasploit module exists for exploitation, and the vulnerability has garnered significant community discussion, indicating potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.0.36CPE matchmatch criteria | cpe:2.3:o:netgear:dgn2200b_firmware:*:*:*:*:*:*:*:* | ||
>= 0, <= 1.0.0.36CPE match | cpe:2.3:h:netgear:dgn2200b:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.