Skip to content
COOEY

EXPOSURES › CVE-2016-6277

CVE-2016-6277

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-6277 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

NETGEAR routers allowed unauthenticated remote code execution via form inputs passed directly to the CLI.

NETGEAR routers permitted unauthenticated web pages to pass form input directly to the command-line interface, enabling remote code execution. DIB organizations must ensure all network hardware is patched and monitored, as this vulnerability was actively exploited in the wild and could lead to network compromise or data exfiltration. Organizations should verify vendor patching timelines and enforce strict network segmentation to limit lateral movement if such devices are compromised.

Shame score — A critical RCE vulnerability in widely deployed consumer/enterprise routers was actively exploited in the wild, indicating severe negligence in patching and security design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.