EXPOSURES › CVE-2016-6277
CVE-2016-6277
HIGH ⌖ ON CISA KEV · EXPLOITEDNETGEAR routers allowed unauthenticated remote code execution via form inputs passed directly to the CLI.
NETGEAR routers permitted unauthenticated web pages to pass form input directly to the command-line interface, enabling remote code execution. DIB organizations must ensure all network hardware is patched and monitored, as this vulnerability was actively exploited in the wild and could lead to network compromise or data exfiltration. Organizations should verify vendor patching timelines and enforce strict network segmentation to limit lateral movement if such devices are compromised.
Shame score — A critical RCE vulnerability in widely deployed consumer/enterprise routers was actively exploited in the wild, indicating severe negligence in patching and security design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.