CVE-2016-6277: NETGEAR Multiple Routers Remote Code Execution Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-03-07. EPSS: 99.8% chance of exploitation in the next 30 days.

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

Affected products

  • NETGEAR d6220 Firmware: up to and including 1.0.0.22
  • NETGEAR d6400 Firmware: up to and including 1.0.0.56
  • NETGEAR r6250 Firmware: up to and including 1.0.4.6_10.1.12
  • NETGEAR r6400 Firmware: up to and including 1.0.1.18
  • NETGEAR r6700 Firmware: up to and including 1.0.1.14
  • NETGEAR r6900 Firmware: up to and including 1.0.1.14
  • NETGEAR r7000 Firmware: up to and including 1.0.7.2_1.1.93
  • NETGEAR r7100lg Firmware: up to and including 1.0.0.28
  • NETGEAR r7300dst Firmware: up to and including 1.0.0.46
  • NETGEAR r7900 Firmware: up to and including 1.0.1.8
  • NETGEAR r8000 Firmware: up to and including 1.0.3.26

Published 2016-12-14. Last modified 2026-06-17.