CVE-2017-6334
HIGH(8.8)KEVLikely Exploited
NETGEAR DGN2200 Devices OS Command Injection Vulnerability
Description
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| netgear | dgn2200 series firmware | <= 10.0.0.50 |
Multiple CVSS Assessments
Source: [email protected](Primary)
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- http://www.securityfocus.com/bid/96463(Broken Link, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/41459/(Exploit, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/41472/(Exploit, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/42257/(Exploit, Third Party Advisory, VDB Entry)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6334(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.