Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Netgear DGN2200B OS Command Injection Vulnerability in PPPoE Configuration

Vulnerability

A command injection vulnerability has been identified in the Netgear DGN2200B router, affecting firmware versions through 1.0.0.36. This vulnerability allows authenticated users to inject and execute arbitrary operating system commands via the pppoe_username parameter in the pppoe.cgi endpoint. Exploitation of this flaw could lead to complete compromise of the device, with the potential for persistent access across reboots, unless the configuration is manually restored.

Impact

Successful exploitation allows authenticated users to execute arbitrary commands on the router's operating system. This could be used to upload and execute a backdoor, compromising the device.

Reproduction

To reproduce this vulnerability, log into the router's web interface using default credentials (admin/admin or admin/password). Navigate to the PPPoE configuration page and send a POST request to the pppoe.cgi endpoint. Include a payload in the pppoe_username parameter that exploits the command injection vulnerability, such as a ping command directed at a controlled IP address. After the command is executed, the original PPPoE configuration will be overwritten, so it is recommended to back up the configuration before exploitation.

Added: Aug 1, 2025, 9:56 PM
Updated: Aug 1, 2025, 9:56 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
6.1
remediation
0.0
relevance
0.3
threat
9.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.