CVE-2016-6277

CVE Published 2016-12-14
Related CWE(s) CWE-352: Cross-Site Request Forgery (CSRF)
Related Vendor(s) netgear
Related Product(s) r7300dst_firmware, r6250_firmware, d6220_firmware, r7000_firmware, r8000_firmware, r7100lg_firmware, r6900_firmware, r6700_firmware, r6400_firmware, d6400_firmware, r7900_firmware
Exploitation Reported (CISA KEV) 2022-03-07
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References