CVE-2013-10060
HIGHNetgear router <1.0.0.36 - Command Injection
Title source: llmDescription
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotehardware
https://www.exploit-db.com/exploits/24974
metasploit
WORKING POC
MANUAL
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/netgear_dgn2200b_pppoe_exec.rb
References (5)
Scores
CVSS v3
7.2
EPSS
0.6101
EPSS Percentile
98.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-78
Status
published
Affected Products (1)
netgear/dgn2200b_firmware
< 1.1.0.36
Timeline
Published
Aug 01, 2025
Tracked Since
Feb 18, 2026