vendor:
DGN2200v1
by:
SivertPL
9
CVSS
CRITICAL
Remote Command Execution (RCE)
78
CWE
Product Name: DGN2200v1
Affected Version From: All prior to v1.0.0.60
Affected Version To: v1.0.0.60
Patch Exists: YES
Related CWE: No CVE number assigned
CPE: h:netgear:dgn2200v1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: UNIX-based systems
2021
Netgear DGN2200v1 – Remote Command Execution (RCE) (Unauthenticated)
NETGEAR DGN2200v1 Unauthenticated Remote Command Execution is a vulnerability that allows an attacker to execute arbitrary commands on the target system without authentication. This vulnerability affects all versions of the DGN2200v1 prior to v1.0.0.60. It is estimated that around 7-10 other models might be or might have been vulnerable in the past. The exploit script only works on UNIX-based systems.
Mitigation:
Update to the latest version of the firmware