peter bassill · operator
$ cve CVE-2017-6366 JSON

CVE-2017-6366 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslookup.cgi. NOTE: this issue can be combined with CVE-2017-6334 to execute arbitrary code remotely.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS3.47% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2017-03-15
Last modified2026-06-17

Affected (5)

VendorProduct
netgeardgn2200 firmware
netgeardgn2200v1
netgeardgn2200v2
netgeardgn2200v3
netgeardgn2200v4

Public exploits

SourceTitleDate
exploit-dbNetgear DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery2017-02-28

References

→ the Explorer  ·  watch your stack  ·  NVD