First published: Wed Dec 14 2016(Updated: )
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR Multiple Devices | ||
All of | ||
Netgear D6220 Firmware | <=1.0.0.22 | |
NETGEAR D6220 firmware | ||
All of | ||
NETGEAR D6400 | <=1.0.0.56 | |
NETGEAR D6400 firmware | ||
All of | ||
Netgear R6250 Firmware | <=1.0.4.6_10.1.12 | |
NETGEAR R6250 | ||
All of | ||
NETGEAR R6400 firmware | <=1.0.1.18 | |
NETGEAR R6400 firmware | ||
All of | ||
NETGEAR R6700 firmware | <=1.0.1.14 | |
NETGEAR R6700v1 firmware | ||
All of | ||
Netgear R6900 Firmware | <=1.0.1.14 | |
Netgear R6900 Firmware | ||
All of | ||
Netgear Nighthawk R7000 Firmware | <=1.0.7.2_1.1.93 | |
NETGEAR Nighthawk R7000 | ||
All of | ||
NETGEAR R7100LG firmware | <=1.0.0.28 | |
Netgear R7100LG | ||
All of | ||
NETGEAR R7300DST firmware | <=1.0.0.46 | |
NETGEAR R7300DST firmware | ||
All of | ||
NETGEAR R7900P firmware | <=1.0.1.8 | |
NETGEAR R7900P firmware | ||
All of | ||
NETGEAR R8000 firmware | <=1.0.3.26 | |
NETGEAR R8000 firmware | ||
Netgear D6220 Firmware | <=1.0.0.22 | |
NETGEAR D6400 | <=1.0.0.56 | |
Netgear R6250 Firmware | <=1.0.4.6_10.1.12 | |
NETGEAR R6400 firmware | <=1.0.1.18 | |
NETGEAR R6700 firmware | <=1.0.1.14 | |
Netgear R6900 Firmware | <=1.0.1.14 | |
Netgear Nighthawk R7000 Firmware | <=1.0.7.2_1.1.93 | |
NETGEAR R7100LG firmware | <=1.0.0.28 | |
NETGEAR R7300DST firmware | <=1.0.0.46 | |
NETGEAR R7900P firmware | <=1.0.1.8 | |
NETGEAR R8000 firmware | <=1.0.3.26 | |
NETGEAR D6220 firmware | ||
NETGEAR D6400 firmware | ||
NETGEAR R6250 | ||
NETGEAR R6400 firmware | ||
NETGEAR R6700v1 firmware | ||
Netgear R6900 Firmware | ||
NETGEAR Nighthawk R7000 | ||
Netgear R7100LG | ||
NETGEAR R7300DST firmware | ||
NETGEAR R7900P firmware | ||
NETGEAR R8000 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-6277 is categorized as high, indicating significant potential impact.
To fix CVE-2016-6277, update your NETGEAR router firmware to the latest available version.
CVE-2016-6277 affects various NETGEAR router models, including R6250, R6400, R6700, and others.
Yes, CVE-2016-6277 can be exploited remotely without the need for local access to the device.
Yes, NETGEAR has released firmware updates that address the vulnerability CVE-2016-6277.