RULE(RULE ID:317624)

Rule General Information
Release Date: 2017-06-27
Rule Name: NETGEAR DGN2200 Remote Code Execution Vulnerability (CVE-2017-6334)
Severity:
CVE ID:
Rule Protection Details
Description: dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Other Unix, Others
Reference: SecurityFocusBID:96463
ExploitDB:41459
Solutions
No information about possible solutions is published. Please use an alternative product to substitude the affected software.