Loading
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.
Use CWE-352, Netgear vendor hub and D6220 Firmware product page to widen CVE-2016-6277 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-45638, CVE-2021-45610 and CVE-2021-45527 for nearby disclosures in the same product family.