漏洞描述 【漏洞对象】NETGEAR_DGN2200 【涉及版本】NETGEAR_DGN2200 【漏洞描述】 NETGEARDGN2200设备上固件版本为10.0.0.50的ping.cgi允许远程身份验证的用户通过HTTPPOST请求的ping_IPAddr字段中的外壳元字符执行任意OS命令。
相关漏洞推荐 POC CVE-2016-5649: NETGEAR DGN2200 / DGND3700 - Admin Password Disclosure POC CVE-2021-20167: Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun POC CVE-2024-30568: Netgear R6850 V1.1.0.88 - Command Injection POC CVE-2024-30569: Netgear R6850 - Information Disclosure POC CVE-2024-30570: Netgear R6850 - Information Disclosure POC CVE-2024-57046: Netgear DGN2200 - Improper Authentication POC CVE-2024-6646: Netgear-WN604 downloadFile.php - Information Disclosure POC netgear-boarddataww-rce: Netgear Devices boardDataWW.php - Remote Command Execution POC dlink-netgear-xss: Dlink DSR-250 and Netgear Prosafe - Cross-Site Scripting POC netgear-dgn-rce: Netgear DGN Devices - Command Execution POC netgear-wnr614-auth-bypass: Netgear WNR614 - Improper Authentication POC netgear-router-auth-bypass: NETGEAR DGN2200v1 - Authentication Bypass Netgear 路由器多版本管理后台 downloadFile.php 信息泄露漏洞(CVE-2024-6646)