CVE-2017-6334
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
The impacted product is end-of-life and should be disconnected if still in use.
A web interface on NETGEAR DGN2200 routers allows authenticated users to run arbitrary commands on the device by injecting shell commands through a DNS lookup form. An attacker with router access can take complete control of the device.
CWE-78 OS Command Injection in dnslookup.cgi POST parameter 'host_name' allows authenticated remote code execution via unvalidated shell metacharacters. Requires prior authentication to the router web interface; successful exploitation grants arbitrary command execution with router privileges.
The full analysis of this CVE is available in Portuguese →