cbcvebase.
CVE-2024-57046
published 2025-02-18

CVE-2024-57046: A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When…

PriorityP181high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
2.08%
79.5th percentile
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.

Affected

1 ranges
VendorProductVersion rangeFixed in
netgeardgn2200_firmware<= 1.0.0.46

Detection & IOCsextracted from sources · hover to see the quote

url/RST_status.htm?x=1.gif
path/RST_status.htm
other?x=1.gif
  • Authentication bypass is confirmed when the first request to /RST_status.htm returns HTTP 401 (unauthenticated) and the second request with the ?x=1.gif suffix returns HTTP 200, indicating the bypass succeeded.
  • Successful exploitation of the bypass on /RST_status.htm will return a body containing both 'Router Status' and 'Show Statistics' strings in the HTTP 200 response.
  • Shodan and FOFA can be used to identify exposed Netgear DGN2200 devices as targets; look for HTTP title 'DGN2200' or 'NETGEAR DGN2200'.
  • ·The authentication bypass only affects Netgear DGN2200 routers running firmware version v1.0.0.46 and earlier. Devices on later firmware are not affected.
  • ·The attack vector is adjacent network (AV:A), meaning the attacker must be on the local network to exploit this vulnerability; it is not directly exploitable from the internet.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.