vendor:
DGN1000B
by:
Netgear
8,8
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: DGN1000B
Affected Version From: V1.1.00.24
Affected Version To: V1.1.00.45
Patch Exists: YES
Related CWE: CVE-2012-6050
CPE: h:netgear:dgn1000b
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
OS Command Injection in the UPNP configuration
The vulnerability is caused by missing input validation in the TimeToLive parameter and can be exploited to inject and execute arbitrary shell commands. It is possible to upload and execute a backdoor to compromise the device.
Mitigation:
Input validation should be implemented to prevent OS command injection attacks.