HTTP: Netgear Multiple Vulnerabilities

This signature detects attempts to exploit a known vulnerability in Netgear routers.

Extended Description

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.

References

BugTraq: 59406 60281

CVE: CVE-2017-6077

Short Name
HTTP:NETGEAR:MULT-VULN
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2013-3071 CVE-2016-10174 CVE-2016-10176 CVE-2017-6077 CVE-2017-6334 Multiple Netgear Vulnerabilities bid:59406 bid:60281
Release Date
06/05/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3377
False Positive
Unknown
CVSS Score

7.5

9.0

10.0

Found a potential security threat?