Executive brief
Multiple NETGEAR routers are vulnerable to remote code execution due to improper sanitization of shell metacharacters in the path info to cgi-bin. An unauthenticated attacker can execute arbitrary commands by passing malicious input through web pages to the command-line interface.
Affected products
- NETGEAR R6250 before 1.0.4.6.Beta
- NETGEAR R6400 before 1.0.1.18.Beta
- NETGEAR R6700 before 1.0.1.14.Beta
- NETGEAR R6900 all
- NETGEAR R7000 before 1.0.7.6.Beta
- NETGEAR R7100LG before 1.0.0.28.Beta
- NETGEAR R7300DST before 1.0.0.46.Beta
- NETGEAR R7900 before 1.0.1.8.Beta
- NETGEAR R8000 before 1.0.3.26.Beta
- NETGEAR D6220 all
- NETGEAR D6400 all
- NETGEAR D7000 all
Timeline
- 2016-12-09: disclosed: Initial vulnerability disclosure (based on BID 94819 date)
- 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog