CVE-2017-6334: NETGEAR DGN2200 Devices OS Command Injection Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 72.6% chance of exploitation in the next 30 days.

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.

Affected products

  • NETGEAR DGN2200 Series Firmware: up to and including 10.0.0.50

Published 2017-03-06. Last modified 2026-06-17.