Netgear DGN1000 and DGN2200 v1 Authentication Bypass Vulnerability Allowing Unauthenticated Remote Code Execution

Vulnerability

An authentication bypass vulnerability has been identified in the Netgear DGN1000 router, affecting firmware versions prior to 1.1.00.48, as well as the DGN2200 v1 model. This vulnerability allows remote, unauthenticated attackers to execute arbitrary operating system commands with root privileges by sending crafted HTTP requests to the setup.cgi endpoint. The embedded web server bypasses authentication checks for certain URLs, enabling exploitation. This vulnerability has been actively exploited since 2017.

Impact

Exploitation of this vulnerability allows for unauthenticated remote code execution on the affected devices, with the executed commands running as the root user.

Reproduction

To reproduce this vulnerability, send a GET request to the setup.cgi endpoint with the 'currentsetting.htm' parameter set to '1'. This request can be made without authentication. Once the authentication bypass is achieved, arbitrary commands can be executed by sending another GET request to the setup.cgi endpoint, this time including the 'todo' parameter set to 'syscmd' and the 'cmd' parameter with the desired command. The output of the executed command will be displayed in the response.

Remediation

Users of the Netgear DGN1000 router should upgrade to firmware version 1.1.00.48. Netgear DGN2200 v1 is no longer supported, but versions v3 and v4 should not be affected by this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
9.1
remediation
6.0
relevance
0.0
threat
7.0
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.