LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-6077: NETGEAR DGN2200 Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 7, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 7, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-6077 to its Known Exploited Vulnerabilities catalog on Mar 7, 2022, with a federal patch deadline of Sep 7, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.

CVE-2017-6077 is a remote code execution vulnerability in the NETGEAR Wireless Router DGN2200. It stems from CWE-78 (OS command injection) and can let an attacker run commands on the device. For IT and security teams, this matters because a compromised edge router can expose the internal network, intercept traffic, or serve as a foothold for further intrusion. Confirm all product and fix details against the vendor advisory.

CISA notes that these routers contain a vulnerability allowing remote code execution and directs organizations to apply updates per vendor instructions. Ransomware use is not documented for this CVE.

How it works

CWE-78 covers improper neutralization of special elements used in an OS command. In products of this class, user-controlled input reaches a shell or system command without adequate validation or escaping. An attacker who can reach the vulnerable interface may supply crafted input that the device interprets as part of a command, leading to arbitrary code execution in the context of the router process.

Public detail on the exact injection point and request format for CVE-2017-6077 is limited in the provided facts. Do not assume specific URLs, parameters, or payloads; treat any unauthenticated or weakly authenticated management or service path on the DGN2200 as in scope until the vendor advisory is reviewed. Successful abuse typically yields control over the device’s operating environment, which can include changing configuration, pivoting to LAN hosts, or altering DNS and routing.

Am I affected? How to find it in your systems

The affected product is the NETGEAR Wireless Router DGN2200. These devices commonly sit at small-office or home-office network edges, providing WAN connectivity, Wi-Fi, and basic NAT/firewall functions. They may still appear in branch offices, labs, or legacy segments even if newer gear is deployed elsewhere.

How to remediate

Patch first. Apply updates per vendor instructions as directed by CISA. Obtain the correct firmware or replacement guidance only from NETGEAR’s official support channels and verify integrity before install. After upgrading, re-check the device model and firmware string against the advisory to confirm the fix is in place.

If you can't patch immediately

Reduce exposure until a vendor-supported fix or hardware replacement is in place.

If your data may have been exposed

Actively exploited remote-code-execution flaws on edge devices can lead to network compromise and data exposure even when ransomware use is not documented for the specific CVE. If you suspect this router was reachable and unpatched, treat connected systems as potentially at risk: rotate credentials that traversed the device, review outbound flows, and check endpoints for follow-on activity. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora, then proceed with broader incident response as needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNETGEAR · Wireless Router DGN2200
WeaknessCWE-78
Added to CISA KEVMar 7, 2022
Federal patch deadlineSep 7, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities