Home / Vulnerabilities / CVE-2017-6334
HIGH SEVERITY
CVE-2017-6334 NETGEAR · DGN2200 Devices

NETGEAR DGN2200 Devices OS Command Injection Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
8.8 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Likelihood

EPSS Prediction

89.21 %
Predictive Probability
Percentile Rank
99.5 th

Documented as more likely to be exploited than 99.5% of known CVEs.

Detection Date

Mar 25, 2022

Remediation Due

Apr 15, 2022

CISA Catalog Active

Threat Analysis

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

Remediation Directive

The impacted product is end-of-life and should be disconnected if still in use.

External Intelligence