CVE-2017-6334

NETGEAR DGN2200 Devices OS Command Injection Vulnerability

8.8
CVSS 3.1
72.6 %
EPSS (current)
2022-03-25
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: NETGEAR / DGN2200 Devices

Published: 2017-03-06 · Due (CISA): 2022-04-15

CWE: CWE-78 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
exploitdb41459Netgear DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution2017-02-25
metasploitexploit/linux/http/netgear_dnslookup_cmd_execexploit/linux/http/netgear_dnslookup_cmd_exec2017-02-25
exploitdb41472Netgear DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery2017-02-28
exploitdb42257Netgear DGN2200 - 'dnslookup.cgi' Command Injection (Metasploit)2017-06-26

References only — no downloads or instructions.

Sources