CVE-2017-6077criticalunder attackCWE-78

CVE-2017-6077

Published · Updated

90Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.8epss 69%
from disclosure to weapon0 days
Published on NVDFeb 22
1st PoCFeb 18
CISA KEV+1839d
exploitation probability
69%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-09-07

Apply updates per vendor instructions.

In short

A vulnerability in NETGEAR DGN2200 routers allows authenticated users to run dangerous commands on the device by injecting shell code into a ping tool. This can let attackers take full control of the router.

Technical detail

CWE-78 command injection in ping.cgi via the ping_IPAddr parameter in HTTP POST requests allows authenticated attackers to execute arbitrary OS commands on affected NETGEAR DGN2200 devices running firmware ≤10.0.0.50. The vulnerability exploits insufficient input validation of shell metacharacters, enabling complete system compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.