CVE-2017-6334
KEVHIGH 9.0EPSS 72.2%
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 72.20% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2022-03-25
- Published
- 2017-03-06
- Updated
- 2026-01-12
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/42257
- https://www.exploit-db.com/exploits/41459
- https://www.exploit-db.com/exploits/41472