← All CVEs

CVE-2016-6277

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-07Remediation due 2022-09-07

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

8.8
CVSS
99.8%
EPSS (exploit prob.)
100th
EPSS percentile
2016-12-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-352

Affected products

VendorProductAffected versions
netgeard6220_firmware<= 1.0.0.22
netgeard6220all versions
netgeard6400_firmware<= 1.0.0.56
netgeard6400all versions
netgearr6250_firmware<= 1.0.4.6_10.1.12
netgearr6250all versions
netgearr6400_firmware<= 1.0.1.18
netgearr6400all versions
netgearr6700_firmware<= 1.0.1.14
netgearr6700all versions
netgearr6900_firmware<= 1.0.1.14
netgearr6900all versions
netgearr7000_firmware<= 1.0.7.2_1.1.93
netgearr7000all versions
netgearr7100lg_firmware<= 1.0.0.28
netgearr7100lgall versions
netgearr7300dst_firmware<= 1.0.0.46
netgearr7300dstall versions
netgearr7900_firmware<= 1.0.1.8
netgearr7900all versions
netgearr8000_firmware<= 1.0.3.26
netgearr8000all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-6277