ZeroHour

CVE-2024-12847

PoC ×2large

Unauthenticated Root RCE in NETGEAR DGN1000 via setup.cgi

CVSS 3.1
9.8 critical
EPSS
30%p98
Published
()
Modified
AI analysis

CVE-2024-12847 is an authentication bypass (CWE-306) in NETGEAR DGN1000 routers that allows a remote, unauthenticated attacker to inject and execute arbitrary operating system commands (CWE-78) as root. The flaw is triggered by sending crafted HTTP requests to the device's setup.cgi endpoint; no credentials or user interaction are required, and the network vector and low complexity yield a critical CVSS 3.1 score of 9.8. A successful attacker gains full root control of the router, which can be used for device compromise, traffic interception, or botnet recruitment. All DGN1000 units running firmware before 1.1.00.48 are affected; these are aging consumer/ISP-supplied routers, many of which remain connected to the public internet with management interfaces exposed. The vulnerability has been exploited in the wild since at least 2017 and was specifically observed by the Shadowserver Foundation on 2025-02-06 UTC; it has two public PoCs on Exploit-DB, a 29.9% EPSS (98th percentile), is not yet in CISA KEV, and broader botnet activity against consumer routers (e.g., RondoDox, reported to target 56 flaws across 30+ device types) suggests continued scanning pressure against this device class.

What to do: Upgrade affected DGN1000 units to firmware 1.1.00.48 or later; if the device is end-of-life or no update is available, block or restrict WAN-side access to the web management interface (particularly setup.cgi) or replace the router. Review device and firewall logs for suspicious unauthenticated requests to setup.cgi, and treat any unit with an internet-exposed management interface as potentially compromised given exploitation has been observed since at least 2017.

Affected
netgear dgn1000 firmwarebefore 1.1.00.48
Estimated exposure
largeon the order of 10,000-100,000 internet-exposed DGN1000 devices (total units shipped over the product's lifetime likely higher) — The DGN1000 was a mass-market, ISP-distributed consumer router whose web management interface has long been visible in internet-wide scans, so exposure is estimated from that scan visibility and the age of the remaining installed base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.

Vendors
netgear
Products
dgn1000 firmware
Weakness
CWE-78, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news