Vulnerability record · CVE-2017-6077 · published 22 February 2017
CVE-2017-6077: NETGEAR DGN2200 ping.cgi OS Command Injection
Netgear · Dgn2200 Firmware
The ping.cgi endpoint on NETGEAR DGN2200 devices with firmware through 10.0.0.50 fails to sanitize the ping_IPAddr field of an HTTP POST request, allowing OS command injection. An attacker who can reach the interface can execute arbitrary commands on the device, which is a router sitting at the network edge.
Description
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing, public exploit code, and very high EPSS probability make this an actively targeted remote code execution flaw on an internet-facing device.
What it is
The ping.cgi endpoint on NETGEAR DGN2200 devices with firmware through 10.0.0.50 fails to sanitize the ping_IPAddr field of an HTTP POST request, allowing OS command injection. An attacker who can reach the interface can execute arbitrary commands on the device, which is a router sitting at the network edge.
Impact
Successful exploitation gives the attacker arbitrary OS command execution on the router, enabling full device compromise, traffic interception or redirection, and use of the device as a foothold into the internal network.
Attack surface
Reached over the network via an HTTP POST to ping.cgi; the description states remote authenticated users, though the CVSS 3.1 vector lists PR:N, so the record is inconsistent on whether credentials are required. No user interaction is indicated.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-03-07, and EPSS shows a 30-day probability of 0.68201 (99.3rd percentile). A public Exploit-DB entry (41394) exists, so exploitation is both public and observed.
What to do
- Apply the vendor firmware update for DGN2200 devices; firmware through 10.0.0.50 is affected.
- If the device cannot be patched or is end-of-life, replace it or remove it from the network.
- Disable remote administration and restrict the management interface to trusted internal hosts only.
- Change default administrative credentials and enforce strong, unique passwords on the device.
- Monitor or block outbound connections from the router to unexpected destinations as a containment measure.
Detection
- Inspect HTTP request logs for POSTs to ping.cgi with shell metacharacters (;, |, &, $(), backticks) in the ping_IPAddr parameter.
- Alert on unexpected outbound connections or processes spawned by the router's web management service.
- Monitor for repeated authentication attempts against the router management interface followed by ping.cgi requests.
- Review network traffic for command-and-control or scanning activity originating from DGN2200 device IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6077 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "NETGEAR DGN2200 Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/96408 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41394/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/96408 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41394/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6077 | US Government Resource |
Track CVE-2017-6077 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6077), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.