CVE-2013-10060
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-01

Last updated on: 2025-09-23

Assigner: VulnCheck

Description
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-01
Last Modified
2025-09-23
Generated
2026-05-06
AI Q&A
2025-08-01
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
netgear dgn2200b_firmware to 1.1.0.36 (inc)
netgear dgn2200b *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an authenticated OS command injection in Netgear routers (specifically tested on the DGN2200B model) with firmware versions 1.0.0.36 and earlier. A remote attacker who has valid credentials can exploit the pppoe.cgi endpoint by sending crafted input to the pppoe_username parameter, allowing them to execute arbitrary operating system commands on the device.


How can this vulnerability impact me? :

This vulnerability can lead to a full compromise of the affected Netgear router device. An attacker with valid credentials can execute arbitrary commands, potentially taking complete control of the device. The compromise may persist even after the device is rebooted unless the configuration is restored, which could lead to ongoing unauthorized access and control.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart