EIP-2026-101865
PRE-CVENetgear DGN2200v1 - Remote Command Execution (RCE) (Unauthenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101865. PoCs published by SivertPL.
AI-analyzed exploit summary This Python script exploits an unauthenticated remote command execution vulnerability in Netgear DGN2200v1 routers by injecting a command into the 'host_name' parameter of the 'dnslookup.cgi' endpoint, which spawns a telnet backdoor. The exploit is functional and demonstrates the vulnerability by opening a reverse shell.
Description
Netgear DGN2200v1 - Remote Command Execution (RCE) (Unauthenticated)
Exploits (1)
This Python script exploits an unauthenticated remote command execution vulnerability in Netgear DGN2200v1 routers by injecting a command into the 'host_name' parameter of the 'dnslookup.cgi' endpoint, which spawns a telnet backdoor. The exploit is functional and demonstrates the vulnerability by opening a reverse shell.