Netgear Vulnerability Vendor: Netgear Product: DG400 Version: 1.0.0.114 Type: Remote Command Execution Author: Jiaqian Peng Institution: pengjiaqian@iie.ac.cn Vulnerability Description We found a Command Injection vulnerability in Netgear router firmware, which allows remote attackers to execute arbitrary OS commands from a crafted request. Remote Command Execution In function, is directly passed by the attacker, allowing control of to attack the OS. The initial input is extracted and causes command injection. POC Set to , and the router will execute it: Result Get a shell!