First published: Mon Mar 06 2017(Updated: )
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Netgear Dgn2200 Series Firmware | <=10.0.0.50 | |
Any of | ||
NETGEAR DGN2200v1 | ||
Netgear Dgn2200v2 | ||
Netgear Dgn2200v3 | ||
Netgear Dgn2200v4 | ||
Netgear Dgn2200 Series Firmware | <=10.0.0.50 | |
NETGEAR DGN2200v1 | ||
Netgear Dgn2200v2 | ||
Netgear Dgn2200v3 | ||
Netgear Dgn2200v4 | ||
NETGEAR DGN2200 Devices | ||
All of | ||
<=10.0.0.50 | ||
Any of | ||
The impacted product is end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.