CVE-2024-12847
PoC ×2largeUnauthenticated Root RCE in NETGEAR DGN1000 via setup.cgi
CVE-2024-12847 is an authentication bypass (CWE-306) in NETGEAR DGN1000 routers that allows a remote, unauthenticated attacker to inject and execute arbitrary operating system commands (CWE-78) as root. The flaw is triggered by sending crafted HTTP requests to the device's setup.cgi endpoint; no credentials or user interaction are required, and the network vector and low complexity yield a critical CVSS 3.1 score of 9.8. A successful attacker gains full root control of the router, which can be used for device compromise, traffic interception, or botnet recruitment. All DGN1000 units running firmware before 1.1.00.48 are affected; these are aging consumer/ISP-supplied routers, many of which remain connected to the public internet with management interfaces exposed. The vulnerability has been exploited in the wild since at least 2017 and was specifically observed by the Shadowserver Foundation on 2025-02-06 UTC; it has two public PoCs on Exploit-DB, a 29.9% EPSS (98th percentile), is not yet in CISA KEV, and broader botnet activity against consumer routers (e.g., RondoDox, reported to target 56 flaws across 30+ device types) suggests continued scanning pressure against this device class.
What to do: Upgrade affected DGN1000 units to firmware 1.1.00.48 or later; if the device is end-of-life or no update is available, block or restrict WAN-side access to the web management interface (particularly setup.cgi) or replace the router. Review device and firewall logs for suspicious unauthenticated requests to setup.cgi, and treat any unit with an internet-exposed management interface as potentially compromised given exploitation has been observed since at least 2017.
| netgear dgn1000 firmware | before 1.1.00.48 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.
- Vendors
- netgear
- Products
- dgn1000 firmware
- Weakness
- CWE-78, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H