Vulnerability record · CVE-2016-6277 · published 14 December 2016
CVE-2016-6277: NETGEAR router cgi-bin command injection allows remote code execution
Netgear · D6220 Firmware
Multiple NETGEAR router models fail to sanitize shell metacharacters in the path info passed to cgi-bin/, allowing remote command execution. The flaw affects a broad set of consumer routers and is listed in CISA's Known Exploited Vulnerabilities catalog, so unpatched devices are a real target.
Description
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with public exploit code and an EPSS near 1.0, and successful exploitation gives full control of an internet-facing device.
What it is
Multiple NETGEAR router models fail to sanitize shell metacharacters in the path info passed to cgi-bin/, allowing remote command execution. The flaw affects a broad set of consumer routers and is listed in CISA's Known Exploited Vulnerabilities catalog, so unpatched devices are a real target.
Impact
An attacker can execute arbitrary commands on the router, gaining full control of the device and its network position. That enables traffic interception, credential capture, and use of the router as a pivot into the internal network.
Attack surface
Reachable over the network via crafted requests to the cgi-bin/ path; the CVSS vector indicates no privileges are required but user interaction is needed. The CWE entry classifies it as CSRF, consistent with a request that must be triggered through a victim's browser or session.
Exploitation
CISA added it to KEV on 2022-03-07 with a 2022-09-07 remediation due date, and EPSS is 0.998 (99.96th percentile). Multiple references are tagged Exploit, including Exploit-DB and Packet Storm entries, confirming public exploit code exists.
What to do
- Apply the vendor firmware updates listed in the NETGEAR advisory (kb.netgear.com/000036386) for each affected model.
- If a model has no fixed firmware, replace it or isolate it on a segmented network with no access to sensitive systems.
- Disable remote administration and UPnP on the router, and restrict the management interface to trusted LAN hosts.
- Change default administrative credentials and review router logs for unexpected cgi-bin requests.
- Track the CISA KEV due date and confirm remediation of all affected devices.
Detection
- Inspect HTTP request logs and IDS/IPS alerts for shell metacharacters (;, |, $(), backticks) in cgi-bin/ path info.
- Monitor router outbound traffic for connections to unknown external hosts that could indicate command-and-control or exfiltration.
- Audit firmware versions of NETGEAR R6250, R6400, R6700, R6900, R7000, R7100LG, R7300DST, R7900, R8000, D6220, D6400, and D7000 devices against the fixed versions.
- Alert on unexpected processes or configuration changes on router management interfaces.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-6277 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "NETGEAR Multiple Routers Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-6277 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6277), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.