peter bassill · operator
$ cve CVE-2016-6277 JSON

CVE-2016-6277 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 99.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-09-07.

Description

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS99.8% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-352
On CISA KEVyes — remediate by 2022-09-07
Public exploityes
Published2016-12-14
Last modified2026-06-17

CISA KEV

NameNETGEAR Multiple Routers Remote Code Execution Vulnerability
Added2022-03-07
Due2022-09-07
Vendor / productNETGEAR / Multiple Routers
Ransomware usenone reported

Affected (22)

VendorProduct
netgeard6220
netgeard6220 firmware
netgeard6400
netgeard6400 firmware
netgearr6250
netgearr6250 firmware
netgearr6400
netgearr6400 firmware
netgearr6700
netgearr6700 firmware
netgearr6900
netgearr6900 firmware
netgearr7000
netgearr7000 firmware
netgearr7100lg
netgearr7100lg firmware
netgearr7300dst
netgearr7300dst firmware
netgearr7900
netgearr7900 firmware
netgearr8000
netgearr8000 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD