CVE-2017-6334
NETGEAR DGN2200 Devices OS Command Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
YesDecision
Descriptions
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
Dnslookup.cgi en dispositivos NETGEAR DGN2200 con firmware hasta la versión 10.0.0.50 permite a usuarios remotos autenticados ejecutar comandos del SO arbitrarios a través de metacaracteres shell en el campo del nombre de host de una solicitud HTTP POST, una vulnerabilidad diferente a CVE-2017-6077.
Netgear DGN2200 versions 1, 2, 3, and 4 suffer from a non-administrative authenticated remote command execution vulnerability via dnslookup.cgi.
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-02-26 CVE Reserved
- 2017-02-26 CVE Published
- 2022-03-25 Exploited in Wild
- 2022-04-15 KEV Due Date
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-22 EPSS Updated
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/96463 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/42257 | 2024-08-05 | |
https://www.exploit-db.com/exploits/41459 | 2024-08-05 | |
https://www.exploit-db.com/exploits/41472 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | Dgn2200 Series Firmware Search vendor "Netgear" for product "Dgn2200 Series Firmware" | <= 10.0.0.50 Search vendor "Netgear" for product "Dgn2200 Series Firmware" and version " <= 10.0.0.50" | - |
Affected
| in | Netgear Search vendor "Netgear" | Dgn2200v1 Search vendor "Netgear" for product "Dgn2200v1" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Dgn2200 Series Firmware Search vendor "Netgear" for product "Dgn2200 Series Firmware" | <= 10.0.0.50 Search vendor "Netgear" for product "Dgn2200 Series Firmware" and version " <= 10.0.0.50" | - |
Affected
| in | Netgear Search vendor "Netgear" | Dgn2200v2 Search vendor "Netgear" for product "Dgn2200v2" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Dgn2200 Series Firmware Search vendor "Netgear" for product "Dgn2200 Series Firmware" | <= 10.0.0.50 Search vendor "Netgear" for product "Dgn2200 Series Firmware" and version " <= 10.0.0.50" | - |
Affected
| in | Netgear Search vendor "Netgear" | Dgn2200v3 Search vendor "Netgear" for product "Dgn2200v3" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Dgn2200 Series Firmware Search vendor "Netgear" for product "Dgn2200 Series Firmware" | <= 10.0.0.50 Search vendor "Netgear" for product "Dgn2200 Series Firmware" and version " <= 10.0.0.50" | - |
Affected
| in | Netgear Search vendor "Netgear" | Dgn2200v4 Search vendor "Netgear" for product "Dgn2200v4" | - | - |
Safe
|