Unrated severityNVD Advisory· Published Aug 1, 2025· Updated Apr 7, 2026
Netgear Routers pppoe.cgi RCE
CVE-2013-10060
Description
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.
Affected products
2- Netgear/DGN2200Bv5Range: *
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/netgear_dgn2200b_pppoe_exec.rbmitreexploit
- web.archive.org/web/20170422033239/http://www.s3cur1ty.de/m1adv2013-015mitretechnical-descriptionexploit
- www.exploit-db.com/exploits/24513mitreexploit
- www.exploit-db.com/exploits/24974mitreexploit
- www.vulncheck.com/advisories/netgear-legacy-routers-rcemitrethird-party-advisory
News mentions
0No linked articles in our index yet.