Cross-Site Request Forgery Vulnerability in NETGEAR DGN2200 Routers
CVE-2017-6366

8.8HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
15 March 2017

Summary

The NETGEAR DGN2200 router is affected by a cross-site request forgery (CSRF) vulnerability that allows remote attackers to hijack user authentication. This vulnerability exists in the firmware versions 10.0.0.20 through 10.0.0.50, enabling unauthorized requests that utilize the host_name parameter in dnslookup.cgi for DNS lookups. Additionally, this vulnerability has the potential to be exploited in conjunction with other vulnerabilities, allowing attackers to execute arbitrary code remotely. Users are advised to update their router firmware to mitigate risks associated with this security flaw.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.