CVE-2017-6077
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
- Affected products
- Netgear Dgn2200
- Netgear dgn2200 Firmware
- ≤ 10.0.0.50
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 68.2% (99th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2017-02-22
CVE-2017-6077 at NVD
5 known exploits for CVE-2017-6077
Proof-of-concept code and exploit modules indexed by Sploitus
VideoLAN VLC Media Player 2.2.5 EphemeralCockroach Heap Overflow Exploit
NETGEAR DGN2200 v1/v2/v3/v4 - Cross-Site Request Forgery Vulnerability
NETGEAR DGN2200v1v2v3v4 - Cross-Site Request Forgery
Netgear DGN2200 Authenticated Remote Command Execution
Netgear DGN2200v1/v2/v3/v4 - 'ping.cgi' Remote Command Execution