CVE-2017-6077
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- NETGEAR DGN2200 Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 68% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-78
מוצרים מושפעים
netgear: dgn2200 firmware; netgear: dgn2200
קישורים
- https://www.exploit-db.com/exploits/41394/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41394/ ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/96408 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/96408 Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource