CVE-2024-35518
Description
Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Netgear EX6120 v1.0.0.68 and prior contain a command injection flaw in genie_fix2.cgi via the wan_dns1_pri parameter, enabling authenticated remote code execution with high privileges.
Vulnerability
The Netgear EX6120 AC1200 Dual Band WiFi Range Extender, firmware version 1.0.0.68 (and likely prior versions), is vulnerable to an authenticated command injection in the genie_fix2.cgi CGI script. The wan_dns1_pri parameter is not properly sanitized, allowing arbitrary shell commands to be injected. The vulnerability exists in the httpd process, libacos_shared.so, and acos_service components [1].
Exploitation
An attacker must be able to authenticate to the administrative web interface (local network access required). Once authenticated, a crafted HTTP POST request to genie_fix2.cgi with a malicious value in the wan_dns1_pri parameter triggers the injection. No user interaction beyond authentication is needed, and the attack complexity is low [1].
Impact
Successful exploitation allows an attacker to execute arbitrary operating system commands with the privileges of the web server (root), leading to full compromise of the device. This results in high impact on confidentiality, integrity, and availability, and the attack can be extended to other devices on the network due to the scope change [1].
Mitigation
Netgear has released fixed firmware version 1.0.0.98 to address this vulnerability. Users should update immediately via the device's administrative interface or from Netgear's support page [1]. There are no known workarounds, and this CVE is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.