Junglewise Threat Intelligence

CVE-2017-6334: NETGEAR DGN2200 Devices OS Command Injection Vulnerability

CVE-2017-6334 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-25

Vendors: NETGEAR.

Executive brief

The dnslookup.cgi component on NETGEAR DGN2200 devices allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request. This vulnerability affects multiple hardware revisions (v1-v4) running firmware versions up to 10.0.0.50.

Affected products

  • NETGEAR DGN2200 firmware through 10.0.0.50
  • NETGEAR DGN2200v1
  • NETGEAR DGN2200v2
  • NETGEAR DGN2200v3
  • NETGEAR DGN2200v4

Timeline

  • 2017-03-07: disclosed: Initial analysis by NIST
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: other: Vulnerability published on NVD