High severity8.8CISA KEVNVD Advisory· Published Mar 6, 2017· Updated Apr 21, 2026
CVE-2017-6334
CVE-2017-6334
Description
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
Affected products
1- cpe:2.3:o:netgear:dgn2200_series_firmware:*:*:*:*:*:*:*:*Range: <=10.0.0.50
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.exploit-db.com/exploits/41459/nvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/41472/nvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/42257/nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/96463nvdBroken LinkThird Party AdvisoryVDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.