Executive brief
The dnslookup.cgi component on NETGEAR DGN2200 devices allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request. This vulnerability affects multiple hardware revisions (v1-v4) running firmware versions up to 10.0.0.50.
Affected products
- NETGEAR DGN2200 firmware through 10.0.0.50
- NETGEAR DGN2200v1
- NETGEAR DGN2200v2
- NETGEAR DGN2200v3
- NETGEAR DGN2200v4
Timeline
- 2017-03-07: disclosed: Initial analysis by NIST
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: other: Vulnerability published on NVD