← Vulnerability feed

Vulnerability record · CVE-2017-6077 · published 22 February 2017

CVE-2017-6077: NETGEAR DGN2200 ping.cgi OS Command Injection

Netgear · Dgn2200 Firmware

The ping.cgi endpoint on NETGEAR DGN2200 devices with firmware through 10.0.0.50 fails to sanitize the ping_IPAddr field of an HTTP POST request, allowing OS command injection. An attacker who can reach the interface can execute arbitrary commands on the device, which is a router sitting at the network edge.

9.8 CVSS 3.1 Critical CISA KEV since 7 Mar 2022 EPSS 69% · top 0.7% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
69%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing, public exploit code, and very high EPSS probability make this an actively targeted remote code execution flaw on an internet-facing device.

What it is

The ping.cgi endpoint on NETGEAR DGN2200 devices with firmware through 10.0.0.50 fails to sanitize the ping_IPAddr field of an HTTP POST request, allowing OS command injection. An attacker who can reach the interface can execute arbitrary commands on the device, which is a router sitting at the network edge.

Impact

Successful exploitation gives the attacker arbitrary OS command execution on the router, enabling full device compromise, traffic interception or redirection, and use of the device as a foothold into the internal network.

Attack surface

Reached over the network via an HTTP POST to ping.cgi; the description states remote authenticated users, though the CVSS 3.1 vector lists PR:N, so the record is inconsistent on whether credentials are required. No user interaction is indicated.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2022-03-07, and EPSS shows a 30-day probability of 0.68201 (99.3rd percentile). A public Exploit-DB entry (41394) exists, so exploitation is both public and observed.

What to do

  • Apply the vendor firmware update for DGN2200 devices; firmware through 10.0.0.50 is affected.
  • If the device cannot be patched or is end-of-life, replace it or remove it from the network.
  • Disable remote administration and restrict the management interface to trusted internal hosts only.
  • Change default administrative credentials and enforce strong, unique passwords on the device.
  • Monitor or block outbound connections from the router to unexpected destinations as a containment measure.

Detection

  • Inspect HTTP request logs for POSTs to ping.cgi with shell metacharacters (;, |, &, $(), backticks) in the ping_IPAddr parameter.
  • Alert on unexpected outbound connections or processes spawned by the router's web management service.
  • Monitor for repeated authentication attempts against the router management interface followed by ping.cgi requests.
  • Review network traffic for command-and-control or scanning activity originating from DGN2200 device IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-6077 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "NETGEAR DGN2200 Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/96408 Broken LinkThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/41394/ ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/96408 Broken LinkThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/41394/ ExploitThird Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6077 US Government Resource

Track CVE-2017-6077 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-38516Netgear d6220 firmware vulnerabilityCertain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D700…EPSS 1.3%9.8CVE-2019-17373Netgear mbr1515 firmware vulnerabilityCertain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg …EPSS 1.5%9.8CVE-2016-5649Netgear dgn2200 firmware cleartext transmission vulnerabilityA vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_…EPSS 24%8.8CVE-2024-57046Netgear dgn2200 firmware improper authentication vulnerabilityA vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authenticati…EPSS 2.1%8.8CVE-2020-35785Netgear dgn2200 firmware improper authentication vulnerabilityNETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-2020-0365).EPSS 0.67%8.8CVE-2017-18755Netgear r6300 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.4.8, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1…EPSS 0.46%8.8CVE-2017-18756Netgear d6220 firmware vulnerabilityCertain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6220 before 1.0.0.32, D6400 before 1.0.0.66, D850…EPSS 0.55%8.8CVE-2017-18842Netgear r7300 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects R7300 before 1.0.0.54, R8500 before 1.0.2.94, DGN2200v1 before 1.0.0.55, and D2200D/D2200D…EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2017-6077), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.