CVE-2016-11054: OS Command Injection
Published Apr 28, 2020
·Updated
NETGEAR DGN2200v4 devices before 2017-01-06 are affected by command execution and an FTP insecure root directory.
Affected Software
2 affected components
Netgear Dgn2200 Firmware<2017-01-06
Netgear DGN2200=v4
Event History
Apr 28, 2020
CVE Published
via MITRE·03:57 PM
Data Sourced
via MITRE·03:57 PM
Description
Frequently Asked Questions
1
What is CVE-2016-11054?
CVE-2016-11054 is a security vulnerability that affects NETGEAR DGN2200v4 devices before 2017-01-06.
2
What is the severity of CVE-2016-11054?
CVE-2016-11054 has a severity rating of 7.2 (critical).
3
How does CVE-2016-11054 affect NETGEAR DGN2200v4 devices?
CVE-2016-11054 allows for command execution and an insecure root directory for FTP on NETGEAR DGN2200v4 devices.
4
How can I determine if my NETGEAR DGN2200v4 device is affected by CVE-2016-11054?
If your NETGEAR DGN2200v4 device has firmware before 2017-01-06, it may be affected by CVE-2016-11054.
5
How can I fix CVE-2016-11054 on my NETGEAR DGN2200v4 device?
To fix CVE-2016-11054, update your NETGEAR DGN2200v4 device firmware to version 2017-01-06 or later.