Umbra Wiki cve cve/CVE-2017-6334
Back to wiki

CVE-2017-6334 — NETGEAR DGN2200 Devices OS Command Injection Vulnerability

provenance: imported · CVE: CVE-2017-6334 · CWE: CWE-78

CVE-2017-6334: NETGEAR DGN2200 Devices OS Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project NETGEAR
Product DGN2200 Devices
Date added 2022-03-25
Due date 2022-04-15
Ransomware campaign use Unknown

Description

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

Required action (CISA)

The impacted product is end-of-life and should be disconnected if still in use.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2017-6334

Weakness behind it

CISA records this vulnerability as an instance of CWE-78. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2017-6334
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →