CVE-2017-6077: NETGEAR DGN2200 Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-07. EPSS: 68.7% chance of exploitation in the next 30 days.
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
Affected products
- NETGEAR DGN2200 Firmware: up to and including 10.0.0.50
Published 2017-02-22. Last modified 2026-06-17.