Back

CRITICAL

Netgear Routers pppoe.cgi RCE

Published Aug 1, 2025

Description

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 1, 2025
Updated May 15, 2026
Reserved Aug 1, 2025
CISA Vulnrichment
Updated Aug 6, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a