CVE-2013-10060: Netgear Routers pppoe.cgi RCE
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoeusername parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-10060?
CVE-2013-10060 has a high severity rating due to its potential for remote command execution.
How do I fix CVE-2013-10060?
To fix CVE-2013-10060, upgrade the firmware of your Netgear DGN2200B router to a version later than 1.0.0.36.
What systems are affected by CVE-2013-10060?
CVE-2013-10060 affects Netgear DGN2200B routers running firmware version 1.0.0.36 and prior.
Can CVE-2013-10060 be exploited remotely?
Yes, CVE-2013-10060 can be exploited remotely by authenticated attackers with valid credentials.
What are the consequences of exploiting CVE-2013-10060?
Exploiting CVE-2013-10060 can allow attackers to execute arbitrary OS commands on the affected router.