Skip to content
COOEY

EXPOSURES › CVE-2017-6334

CVE-2017-6334

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-6334 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

NETGEAR DGN2200 devices with firmware through 10.0.0.50 allow remote authenticated users to execute arbitrary OS commands via OS command injection in dnslookup.cgi.

This OS command injection flaw in NETGEAR DGN2200 devices enables attackers to execute arbitrary commands on the device once authenticated, representing a severe security failure. DIB organizations must ensure all network hardware is patched to the latest firmware to prevent exploitation, as this vulnerability is actively exploited in the wild and could lead to device compromise, data exfiltration, or lateral movement within a network.

Shame score — A critical OS command injection vulnerability in widely deployed consumer/enterprise networking hardware that was actively exploited in the wild, indicating a failure to patch known, severe flaws in time.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.