Description
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.
Published: 2016-12-14
Score: 8.8 High
EPSS: 94.3% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Tue, 04 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-03-07'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Netgear D6220 D6220 Firmware D6400 D6400 Firmware R6250 R6250 Firmware R6400 R6400 Firmware R6700 R6700 Firmware R6900 R6900 Firmware R7000 R7000 Firmware R7100lg R7100lg Firmware R7300dst R7300dst Firmware R7900 R7900 Firmware R8000 R8000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-21T23:55:47.695Z

Reserved: 2016-07-22T00:00:00.000Z

Link: CVE-2016-6277

cve-icon Vulnrichment

Updated: 2024-08-06T01:22:20.753Z

cve-icon NVD

Status : Deferred

Published: 2016-12-14T16:59:00.350

Modified: 2025-10-22T00:15:54.440

Link: CVE-2016-6277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses