Vulnerability Description
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | D6220 Firmware | <= 1.0.0.22 |
| Netgear | D6220 | - |
| Netgear | D6400 Firmware | <= 1.0.0.56 |
| Netgear | D6400 | - |
| Netgear | R6250 Firmware | <= 1.0.4.6_10.1.12 |
| Netgear | R6250 | - |
| Netgear | R6400 Firmware | <= 1.0.1.18 |
| Netgear | R6400 | - |
| Netgear | R6700 Firmware | <= 1.0.1.14 |
| Netgear | R6700 | - |
| Netgear | R6900 Firmware | <= 1.0.1.14 |
| Netgear | R6900 | - |
| Netgear | R7000 Firmware | <= 1.0.7.2_1.1.93 |
| Netgear | R7000 | - |
| Netgear | R7100Lg Firmware | <= 1.0.0.28 |
| Netgear | R7100Lg | - |
| Netgear | R7300Dst Firmware | <= 1.0.0.46 |
| Netgear | R7300Dst | - |
| Netgear | R7900 Firmware | <= 1.0.1.8 |
| Netgear | R7900 | - |
Related Weaknesses (CWE)
References
- http://kb.netgear.com/000036386/CVE-2016-582384PatchVendor Advisory
- http://packetstormsecurity.com/files/155712/Netgear-R6400-Remote-Code-Execution.ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/94819Broken LinkThird Party AdvisoryVDB Entry
- http://www.sj-vs.net/a-temporary-fix-for-cert-vu582384-cwe-77-on-netgear-r7000-aBroken LinkMitigationThird Party Advisory
- https://kalypto.org/research/netgear-vulnerability-expanded/Broken LinkExploitThird Party Advisory
- https://www.exploit-db.com/exploits/40889/Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41598/ExploitThird Party AdvisoryVDB Entry
- https://www.kb.cert.org/vuls/id/582384Third Party AdvisoryUS Government Resource
- http://kb.netgear.com/000036386/CVE-2016-582384PatchVendor Advisory
- http://packetstormsecurity.com/files/155712/Netgear-R6400-Remote-Code-Execution.ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/94819Broken LinkThird Party AdvisoryVDB Entry
- http://www.sj-vs.net/a-temporary-fix-for-cert-vu582384-cwe-77-on-netgear-r7000-aBroken LinkMitigationThird Party Advisory
- https://kalypto.org/research/netgear-vulnerability-expanded/Broken LinkExploitThird Party Advisory
- https://www.exploit-db.com/exploits/40889/Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41598/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2016-6277?
CVE-2016-6277 is a vulnerability with a CVSS score of 8.8 (HIGH). NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1...
How severe is CVE-2016-6277?
CVE-2016-6277 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-6277?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear D6220 Firmware, Netgear D6220, Netgear D6400 Firmware, Netgear D6400, Netgear R6250 Firmware.