CVE-2024-57046
published 2025-02-18CVE-2024-57046: A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When…
PriorityP181high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
2.08%
79.5th percentile
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | dgn2200_firmware | <= 1.0.0.46 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Authentication bypass is confirmed when the first request to /RST_status.htm returns HTTP 401 (unauthenticated) and the second request with the ?x=1.gif suffix returns HTTP 200, indicating the bypass succeeded. ↗
- →Successful exploitation of the bypass on /RST_status.htm will return a body containing both 'Router Status' and 'Show Statistics' strings in the HTTP 200 response. ↗
- →Shodan and FOFA can be used to identify exposed Netgear DGN2200 devices as targets; look for HTTP title 'DGN2200' or 'NETGEAR DGN2200'. ↗
- ·The authentication bypass only affects Netgear DGN2200 routers running firmware version v1.0.0.46 and earlier. Devices on later firmware are not affected. ↗
- ·The attack vector is adjacent network (AV:A), meaning the attacker must be on the local network to exploit this vulnerability; it is not directly exploitable from the internet. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cg2m-239p-9xhp: A vulnerability in the Netgear DGN2200 router with firmware version v1
ghsa_unreviewed·2025-02-18
CVE-2024-57046 [HIGH] CWE-287 GHSA-cg2m-239p-9xhp: A vulnerability in the Netgear DGN2200 router with firmware version v1
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.
VulnCheck
NETGEAR dgn2200_firmware Improper Authentication
vulncheck·2024·CVSS 8.8
CVE-2024-57046 [HIGH] NETGEAR dgn2200_firmware Improper Authentication
NETGEAR dgn2200_firmware Improper Authentication
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.
Affected: NETGEAR dgn2200_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2024-57046&date=2026-04-12
No detection rules found.
Nuclei
Netgear DGN2200 - Improper Authentication
nuclei·CVSS 8.8
CVE-2024-57046 [HIGH] Netgear DGN2200 - Improper Authentication
Netgear DGN2200 - Improper Authentication
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the requested url, it will be recognized as passing the authentication.
Template:
id: CVE-2024-57046
info:
name: Netgear DGN2200 - Improper Authentication
author: ritikchaddha
severity: high
description: |
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the requested url, it will be recognized as passing the authentication.
impact: |
Attackers on the local network can bypass authentication by appending '?x=1.gif' to URLs, gaining unauthoriz
2025-02-18
Published
Exploited in the wild