ZeroHour

CVE-2017-6334

KEV PoC ×3mass

Authenticated OS Command Injection in NETGEAR DGN2200 dnslookup.cgi

CISA: NETGEAR DGN2200 Devices OS Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
72%p99
Published
()
KEV added
AI analysis

The dnslookup.cgi endpoint on NETGEAR DGN2200 devices running firmware through 10.0.0.50 does not properly sanitize the host_name field, allowing shell metacharacters submitted in an HTTP POST request to be executed as OS commands on the router. A remote attacker who can authenticate to the web interface (the flaw requires valid credentials but no user interaction) gains arbitrary command execution with the device's privileges, enabling full compromise of the gateway including configuration changes, traffic manipulation, and botnet recruitment. All DGN2200-series devices on firmware 10.0.0.50 or earlier are affected, and the product line is end-of-life, so no patched firmware is expected. Exploitation is established: the flaw carries a 72.2% EPSS score, has three public PoC exploits on Exploit-DB, was added to the CISA KEV catalog on 2022-03-25, and was included among the 33 exploits used by the BotenaGo botnet targeting millions of IoT devices.

What to do: Because the DGN2200 is end-of-life with no fixed firmware available, CISA's required action is to disconnect or replace the device if it is still in use. If replacement must be deferred, do not expose the router's web management interface to the internet, use strong and unique admin credentials, and review logs for unexpected authenticated POST requests to dnslookup.cgi containing metacharacters.

Affected
NETGEAR DGN2200 series firmware (dnslookup.cgi)all firmware through 10.0.0.50
Estimated exposure
mass≈ millions of consumer DSL gateways historically deployed (widely bundled by ISPs; now EOL, unknown how many remain in service) — The DGN2200 was one of Netgear's most heavily distributed consumer DSL gateway lines through retail and ISP bundle channels, with cumulative deployments historically in the millions and the related BotenaGo campaign targeting millions of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.

CISA Known Exploited Vulnerability
Affected
NETGEAR DGN2200 Devices
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
netgear
Products
dgn2200 series firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news