CVE-2017-6077
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
A vulnerability in NETGEAR DGN2200 routers allows authenticated users to run dangerous commands on the device by injecting shell code into a ping tool. This can let attackers take full control of the router.
CWE-78 command injection in ping.cgi via the ping_IPAddr parameter in HTTP POST requests allows authenticated attackers to execute arbitrary OS commands on affected NETGEAR DGN2200 devices running firmware ≤10.0.0.50. The vulnerability exploits insufficient input validation of shell metacharacters, enabling complete system compromise.
The full analysis of this CVE is available in Portuguese →