CVE-2017-6334
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
- Affected products
- Netgear Dgn2200
- Netgear dgn2200 Series Firmware
- ≤ 10.0.0.50
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 72.2% (99th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2017-03-06
CVE-2017-6334 at NVD
11 known exploits for CVE-2017-6334
Proof-of-concept code and exploit modules indexed by Sploitus
VideoLAN VLC Media Player 2.2.5 EphemeralCockroach Heap Overflow Exploit
Netgear DGN2200 - dnslookup.cgi Command Injection Exploit
Netgear DGN2200 - 'dnslookup.cgi' Command Injection (Metasploit)
Netgear DGN2200 dnslookup.cgi Command Injection
NETGEAR DGN2200 v1/v2/v3/v4 - Cross-Site Request Forgery Vulnerability
NETGEAR DGN2200v1v2v3v4 - Cross-Site Request Forgery
Netgear DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery
NETGEAR DGN2200 v1/v2/v3/v4 - dnslookup.cgi Remote Command Execution Exploit
Netgear DGN2201 v1/v2/v3/v4 dnslookup.cgi Remote Command Execution
Netgear DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution
Netgear DGN2200 dnslookup.cgi Command Injection