VulnerabilityAnalyzed
CVE-2017-6334
NETGEAR DGN2200 Devices OS Command Injection Vulnerability
KEVHIGH 8.8EPSS 72.2%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 72.20% probability · 99th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-78
- Affected
- netgear/dgn2200 series firmware
- Source
- cve@mitre.org
CISA notes
The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2017-6334
References
- http://www.securityfocus.com/bid/96463Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41459/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41472/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42257/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/96463Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41459/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41472/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42257/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6334US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.