RULE(RULE ID:331995)

Rule General Information
Release Date: 2020-09-16
Rule Name: Netgear DGN2200 Remote Code Execution Vulnerability (CVE-2017-6077)
Severity:
CVE ID:
Rule Protection Details
Description: ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Network Device
Reference: SecurityFocusBID:96408
ExploitDB:41394
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.netgear.com/