Description
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
Published: 2017-03-06
Score: 8.8 High
EPSS: 89.2% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Tue, 04 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-03-25'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Netgear Dgn2200 Series Firmware Dgn2200v1 Dgn2200v2 Dgn2200v3 Dgn2200v4
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-12T22:19:45.395Z

Reserved: 2017-02-26T00:00:00.000Z

Link: CVE-2017-6334

cve-icon Vulnrichment

Updated: 2024-08-05T15:25:49.088Z

cve-icon NVD

Status : Analyzed

Published: 2017-03-06T02:59:00.433

Modified: 2026-04-21T17:43:06.590

Link: CVE-2017-6334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses