9.8 CVE-2017-6077

Enriched by CISA CISA Kev Catalog Exploit
 

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
https://nvd.nist.gov/vuln/detail/CVE-2017-6077

Categories

CWE-78

References

134c704f-9b21-4f2e-91b3-4a467353bcc0

af854a3a-2127-422b-91ae-364da2661108 Exploit

http://www.securityfocus.com/bid/96408
Broken Link Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/41394/
Exploit Third Party Advisory VDB Entry

cve@mitre.org Exploit

http://www.securityfocus.com/bid/96408
Broken Link Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/41394/
Exploit Third Party Advisory VDB Entry


 

AFFECTED (from MITRE)


Vendor Product Versions
n/a n/a
  • n/a [affected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end
Configuration 1
AND
   cpe:2.3:o:netgear:dgn2200_firmware:*:*:*:*:*:*:*:* <= 10.0.0.50
  Running on/with
  cpe:2.3:h:netgear:dgn2200:-:*:*:*:*:*:*:*


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
https://www.exploit-db.com/exploits/41394/
https://www.exploit-db.com/exploits/41394/


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry