Cross-Site Request Forgery Vulnerability in NETGEAR DGN2200 Routers
CVE-2017-6366
8.8HIGH
Summary
The NETGEAR DGN2200 router is affected by a cross-site request forgery (CSRF) vulnerability that allows remote attackers to hijack user authentication. This vulnerability exists in the firmware versions 10.0.0.20 through 10.0.0.50, enabling unauthorized requests that utilize the host_name parameter in dnslookup.cgi for DNS lookups. Additionally, this vulnerability has the potential to be exploited in conjunction with other vulnerabilities, allowing attackers to execute arbitrary code remotely. Users are advised to update their router firmware to mitigate risks associated with this security flaw.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved