LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-6334: NETGEAR DGN2200 Devices OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-6334 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

CVE-2017-6334 is an OS command injection weakness in NETGEAR DGN2200 devices. According to the CISA summary, the dnslookup.cgi component on devices with firmware through 10.0.0.50 lets remote authenticated users run arbitrary operating-system commands. Because these routers often sit at the network edge, successful abuse can give an attacker a foothold to alter configuration, pivot inward, or disrupt connectivity. The product is end-of-life; CISA’s required action is to disconnect any remaining units still in use.

How it works

The flaw belongs to CWE-78: improper neutralization of special elements used in an OS command. In this class of weakness, user-supplied input reaches a shell or system call without adequate sanitization. On the affected DGN2200 devices the dnslookup.cgi interface accepts input that is later incorporated into a command executed by the device’s operating system. An attacker who already possesses valid credentials can craft that input so the device runs commands of the attacker’s choosing rather than the intended lookup. Exact request format and parameter names are not detailed here; confirm them against the vendor advisory. No public detail in the supplied record describes unauthenticated access or automated worm-style spread, so treat the prerequisite as remote authenticated access.

Am I affected? How to find it in your systems

NETGEAR DGN2200 units are consumer and small-office DSL/router appliances. They commonly appear in branch offices, home offices, and legacy ISP-supplied deployments. Inventory steps:

Because the product is end-of-life, any still-powered unit should be treated as in-scope until it is removed.

How to remediate

The definitive remediation stated by CISA is to disconnect the impacted product if it is still in use; it is end-of-life and no longer receives security updates. If a vendor firmware update that fully addresses CVE-2017-6334 exists for a specific hardware revision, apply that update only after confirming the fixed version in the official NETGEAR advisory. After any change, re-verify that dnslookup.cgi no longer accepts unsanitized input and that management access is restricted. Replace the device with a currently supported model that receives ongoing patches, then retire the old unit from the network.

If you can't patch immediately

Until the device can be removed or replaced, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited router vulnerabilities can lead to network compromise and subsequent data exposure. Known ransomware use of this specific CVE is not documented in the supplied record, but any confirmed intrusion should trigger normal incident-response steps: isolate the device, preserve logs, rotate credentials that traversed the router, and examine internal systems for lateral movement. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNETGEAR · DGN2200 Devices
WeaknessCWE-78
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities