← Back to CVE List
Vulnerability Intelligence Report
NETGEAR Multiple Routers Remote Code Execution Vulnerability

CVE-2016-6277

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

CISA KEV Nuclei Template SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:99.78%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-352 ↗CWE-352 Cross-Site Request Forgery (CSRF)

Affected Products & Versions

Vendor Product Affected Versions
netgear d6220_firmware all
netgear d6220 all
netgear d6400_firmware all
netgear d6400 all
netgear r6250_firmware all
netgear r6250 all
netgear r6400_firmware all
netgear r6400 all
netgear r6700_firmware all
netgear r6700 all
netgear r6900_firmware all
netgear r6900 all
netgear r7000_firmware all
netgear r7000 all
netgear r7100lg_firmware all
netgear r7100lg all
netgear r7300dst_firmware all
netgear r7300dst all
netgear r7900_firmware all
netgear r7900 all
netgear r8000_firmware all
netgear r8000 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.781%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2016-07-22T00:00:00
Published2016-12-14T16:00:00
Patch Date2016-12-07
Last Updated2025-10-21T23:55:47

LINK COPIED TO CLIPBOARD