CVE-2017-6334
KEV PoC ×3massAuthenticated OS Command Injection in NETGEAR DGN2200 dnslookup.cgi
CISA: NETGEAR DGN2200 Devices OS Command Injection Vulnerability
The dnslookup.cgi endpoint on NETGEAR DGN2200 devices running firmware through 10.0.0.50 does not properly sanitize the host_name field, allowing shell metacharacters submitted in an HTTP POST request to be executed as OS commands on the router. A remote attacker who can authenticate to the web interface (the flaw requires valid credentials but no user interaction) gains arbitrary command execution with the device's privileges, enabling full compromise of the gateway including configuration changes, traffic manipulation, and botnet recruitment. All DGN2200-series devices on firmware 10.0.0.50 or earlier are affected, and the product line is end-of-life, so no patched firmware is expected. Exploitation is established: the flaw carries a 72.2% EPSS score, has three public PoC exploits on Exploit-DB, was added to the CISA KEV catalog on 2022-03-25, and was included among the 33 exploits used by the BotenaGo botnet targeting millions of IoT devices.
What to do: Because the DGN2200 is end-of-life with no fixed firmware available, CISA's required action is to disconnect or replace the device if it is still in use. If replacement must be deferred, do not expose the router's web management interface to the internet, use strong and unique admin credentials, and review logs for unexpected authenticated POST requests to dnslookup.cgi containing metacharacters.
| NETGEAR DGN2200 series firmware (dnslookup.cgi) | all firmware through 10.0.0.50 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
- Affected
- NETGEAR DGN2200 Devices
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- netgear
- Products
- dgn2200 series firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H