VulnerabilityAnalyzed
CVE-2017-6077
NETGEAR DGN2200 Remote Code Execution Vulnerability
KEVCRITICAL 9.8EPSS 68.2%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 7 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 68.20% probability · 99th percentile
- CISA KEV
- Listed 7 March 2022 · due 7 September 2022
- Weakness
- CWE-78
- Affected
- netgear/dgn2200 firmware
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-6077
References
- http://www.securityfocus.com/bid/96408Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41394/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/96408Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41394/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6077US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.