← Vulnerability feed

Vulnerability record · CVE-2016-6277 · published 14 December 2016

CVE-2016-6277: NETGEAR router cgi-bin command injection allows remote code execution

Netgear · D6220 Firmware

Multiple NETGEAR router models fail to sanitize shell metacharacters in the path info passed to cgi-bin/, allowing remote command execution. The flaw affects a broad set of consumer routers and is listed in CISA's Known Exploited Vulnerabilities catalog, so unpatched devices are a real target.

8.8 CVSS 3.1 High CISA KEV since 7 Mar 2022 EPSS 100% · top 0.1% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score, v2 9.3
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
11Affected product versions listed by NVD
17References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with public exploit code and an EPSS near 1.0, and successful exploitation gives full control of an internet-facing device.

What it is

Multiple NETGEAR router models fail to sanitize shell metacharacters in the path info passed to cgi-bin/, allowing remote command execution. The flaw affects a broad set of consumer routers and is listed in CISA's Known Exploited Vulnerabilities catalog, so unpatched devices are a real target.

Impact

An attacker can execute arbitrary commands on the router, gaining full control of the device and its network position. That enables traffic interception, credential capture, and use of the router as a pivot into the internal network.

Attack surface

Reachable over the network via crafted requests to the cgi-bin/ path; the CVSS vector indicates no privileges are required but user interaction is needed. The CWE entry classifies it as CSRF, consistent with a request that must be triggered through a victim's browser or session.

Exploitation

CISA added it to KEV on 2022-03-07 with a 2022-09-07 remediation due date, and EPSS is 0.998 (99.96th percentile). Multiple references are tagged Exploit, including Exploit-DB and Packet Storm entries, confirming public exploit code exists.

What to do

  • Apply the vendor firmware updates listed in the NETGEAR advisory (kb.netgear.com/000036386) for each affected model.
  • If a model has no fixed firmware, replace it or isolate it on a segmented network with no access to sensitive systems.
  • Disable remote administration and UPnP on the router, and restrict the management interface to trusted LAN hosts.
  • Change default administrative credentials and review router logs for unexpected cgi-bin requests.
  • Track the CISA KEV due date and confirm remediation of all affected devices.

Detection

  • Inspect HTTP request logs and IDS/IPS alerts for shell metacharacters (;, |, $(), backticks) in cgi-bin/ path info.
  • Monitor router outbound traffic for connections to unknown external hosts that could indicate command-and-control or exfiltration.
  • Audit firmware versions of NETGEAR R6250, R6400, R6700, R6900, R7000, R7100LG, R7300DST, R7900, R8000, D6220, D6400, and D7000 devices against the fixed versions.
  • Alert on unexpected processes or configuration changes on router management interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-6277 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "NETGEAR Multiple Routers Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kb.netgear.com/000036386/CVE-2016-582384 PatchVendor Advisory
http://packetstormsecurity.com/files/155712/Netgear-R6400-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/94819 Broken LinkThird Party AdvisoryVDB Entry
http://www.sj-vs.net/a-temporary-fix-for-cert-vu582384-cwe-77-on-netgear-r7000-and-r6400-routers/ Broken LinkMitigationThird Party Advisory
https://kalypto.org/research/netgear-vulnerability-expanded/ Broken LinkExploitThird Party Advisory
https://www.exploit-db.com/exploits/40889/ Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/41598/ ExploitThird Party AdvisoryVDB Entry
https://www.kb.cert.org/vuls/id/582384 Third Party AdvisoryUS Government Resource
http://kb.netgear.com/000036386/CVE-2016-582384 PatchVendor Advisory
http://packetstormsecurity.com/files/155712/Netgear-R6400-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/94819 Broken LinkThird Party AdvisoryVDB Entry
http://www.sj-vs.net/a-temporary-fix-for-cert-vu582384-cwe-77-on-netgear-r7000-and-r6400-routers/ Broken LinkMitigationThird Party Advisory
https://kalypto.org/research/netgear-vulnerability-expanded/ Broken LinkExploitThird Party Advisory
https://www.exploit-db.com/exploits/40889/ Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/41598/ ExploitThird Party AdvisoryVDB Entry
https://www.kb.cert.org/vuls/id/582384 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6277 US Government Resource

Track CVE-2016-6277 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-5521NETGEAR router web management password disclosure via recovery tokenMultiple NETGEAR router models expose the admin password through the web management server. When authentication is canceled and password recovery is …KEVEPSS 89%analysed9.8CVE-2023-36187Netgear cbr40 firmware classic buffer overflow vulnerabilityBuffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via craf…EPSS 1.1%9.8CVE-2023-34563Netgear r6250 firmware classic buffer overflow vulnerabilitynetgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.EPSS 14%9.8CVE-2023-33532Netgear r6250 firmware command injection vulnerabilityThere is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges…EPSS 16%9.8CVE-2023-30280Netgear r6900 firmware classic buffer overflow vulnerabilityBuffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary …EPSS 1.2%9.8CVE-2021-45638Netgear d6220 firmware out-of-bounds write vulnerabilityCertain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.68, D6400 befor…EPSS 1.5%9.8CVE-2021-45610Netgear d6220 firmware classic buffer overflow vulnerabilityCertain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.66, D6400 before 1.0.0.100,…EPSS 1.4%9.8CVE-2021-45609Netgear d8500 firmware classic buffer overflow vulnerabilityCertain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6250 before 1.0.4.48, …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2016-6277), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.