ZeroHour

CVE-2017-6077

KEV PoC large

Command Injection RCE in NETGEAR DGN2200 Router ping.cgi

CISA: NETGEAR DGN2200 Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
68%p99
Published
()
KEV added
AI analysis

ping.cgi on NETGEAR DGN2200 routers running firmware through version 10.0.0.50 fails to sanitize the ping_IPAddr field of HTTP POST requests, allowing shell metacharacters to inject arbitrary operating-system commands (CWE-78, OS command injection). Per the vulnerability description, an attacker needs authenticated access to the router's web interface to send the crafted POST request, although the CVSS vector treats the flaw as exploitable over the network without privileges — significant because many deployed routers use default or weak admin credentials. Successful exploitation yields arbitrary command execution on the device, enabling full router compromise, manipulation of DNS or routing, interception of traffic, and pivoting into the local network. All NETGEAR DGN2200 (Wireless Router) units on affected firmware are exposed, particularly those with the management interface reachable from the WAN. The flaw is actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2022-03-07, carries a high exploitation probability (EPSS 68.2%, 99th percentile), and a public proof-of-concept is available (Exploit-DB 41394).

What to do: Upgrade DGN2200 firmware to a version later than 10.0.0.50 per NETGEAR's guidance, as required by the CISA KEV listing; if the device is end-of-life and no fixed firmware is available, plan replacement. As interim mitigations, disable WAN-side remote management, restrict the admin interface to trusted hosts, and replace default credentials, since authenticated access is the trigger. Check web server logs for HTTP POST requests to ping.cgi containing shell metacharacters in the ping_IPAddr parameter.

Affected
NETGEAR DGN2200 Wireless Router (ping.cgi web interface)firmware through 10.0.0.50 (inclusive)
Estimated exposure
largeon the order of tens of thousands of internet-exposed DGN2200 routers (legacy ISP-bundled ADSL units); total deployed base likely higher — The DGN2200 was a mass-market ADSL2+ modem-router widely bundled by ISPs, and historical public internet scans have shown tens of thousands of DGN2200 admin interfaces still reachable online, though exact current counts vary.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

CISA Known Exploited Vulnerability
Affected
NETGEAR Wireless Router DGN2200
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
netgear
Products
dgn2200 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news