EXPOSURES › CVE-2017-6334
CVE-2017-6334
HIGH ⌖ ON CISA KEV · EXPLOITEDNETGEAR DGN2200 devices with firmware through 10.0.0.50 allow remote authenticated users to execute arbitrary OS commands via OS command injection in dnslookup.cgi.
This OS command injection flaw in NETGEAR DGN2200 devices enables attackers to execute arbitrary commands on the device once authenticated, representing a severe security failure. DIB organizations must ensure all network hardware is patched to the latest firmware to prevent exploitation, as this vulnerability is actively exploited in the wild and could lead to device compromise, data exfiltration, or lateral movement within a network.
Shame score — A critical OS command injection vulnerability in widely deployed consumer/enterprise networking hardware that was actively exploited in the wild, indicating a failure to patch known, severe flaws in time.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands