Back to search
CVE-2013-10060
Published: Aug 1, 2025
Modified: May 15, 2026
PUBLISHED
Description
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.
| Vendor | Product | Versions |
|---|---|---|
Netgear | DGN2200B | affected 0 - <= 1.0.0.36 |
Weaknesses (CWE)
References
https://web.archive.org/web/20170422033239/http://www.s3cur1ty.de/m1adv2013-015
technical-description
exploit
https://www.vulncheck.com/advisories/netgear-legacy-routers-rce
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now