CVE-2017-11588: Cisco Residential Gateway Firmware
Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is remote command execution via shell metacharacters in the pingAddr parameter to the waitPingqry.cgi URI. The command output is visible at /PingMsg.cmd.
Affected products
- Cisco Residential Gateway Firmware: version ddr2200b-na-annexa-fcc-v00.00.03.45.4e only; version ddr2201v1-na-annexa-fcc-v00.00.03.28.3 only
Published 2017-07-24. Last modified 2026-06-17.