Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
CriticalPublic exploit

Authentication Bypass and Root Command Execution in NETGEAR DGN1000 setup.cgi

IdentifiersCVE-2024-12847CWE-306· Missing Authentication for…

NETGEAR DGN1000 devices running firmware before 1.1.00.48 are affected by an authentication bypass in the web management interface. According to the provided content, a remote unauthenticated attacker can send crafted HTTP requests to the setup.cgi endpoint and bypass authentication, resulting in arbitrary operating system command execution as root. The issue is exposed over HTTP on the device management interface and combines access control failure with command execution through the CGI handler.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows a remote attacker with no prior authentication to execute arbitrary OS commands with root privileges on the affected router. This can lead to full device compromise, configuration manipulation, malware or botnet installation, traffic interception or redirection, persistence, and use of the device as a foothold for further network activity. The content also indicates the vulnerability has been exploited in the wild since at least 2017.

Mitigation

If you can’t patch tonight, do this now.

Restrict access to the router's web management interface, especially from the public internet. Disable remote administration if not required. Place management interfaces behind trusted networks or VPN access controls, apply network segmentation, and continuously monitor for suspicious HTTP requests to setup.cgi and signs of post-compromise activity. For internet-exposed or unsupported devices, immediate isolation or replacement is advisable.

Remediation

Patch, then assume compromise.

Upgrade NETGEAR DGN1000 firmware to version 1.1.00.48 or later. If the device is end-of-life or no fixed firmware is available for a deployed unit, replace the device with supported hardware. Verify that remote management exposure is minimized after upgrade and review the device for signs of compromise if it has been internet-exposed.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
NetgearDgn1000 Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity4

Community discussion across Reddit, Mastodon, and other social sources.