Executive brief
The ping.cgi component on NETGEAR DGN2200 devices allows remote attackers to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request. This command injection vulnerability can be exploited by authenticated users, though some assessments indicate it may be reachable without authentication.
Affected products
- NETGEAR DGN2200 firmware through 10.0.0.50
- NETGEAR DGN2200
Timeline
- 2017-02-22: disclosed: NVD Published Date
- 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog