Umbra Wiki cve cve/CVE-2017-6334
Back to wiki

CVE-2017-6334 — NETGEAR DGN2200 Devices OS Command Injection Vulnerability

provenance: imported · CVE: CVE-2017-6334

CVE-2017-6334: NETGEAR DGN2200 Devices OS Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project NETGEAR
Product DGN2200 Devices
Date added 2022-03-25
Due date 2022-04-15
Ransomware campaign use Unknown

Description

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

Required action (CISA)

The impacted product is end-of-life and should be disconnected if still in use.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2017-6334

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2017-6334
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog