PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-6334 NETGEAR CVE debrief

CVE-2017-6334 is an OS command injection vulnerability affecting NETGEAR DGN2200 devices. CISA lists it in the Known Exploited Vulnerabilities catalog, which indicates known exploitation and raises the urgency for defenders. CISA’s noted required action is to disconnect the impacted product if it is still in use, because the product is end-of-life.

Vendor
NETGEAR
Product
DGN2200 Devices
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-03-25
Original CVE updated
2022-03-25
Advisory published
2022-03-25
Advisory updated
2022-03-25

Who should care

Organizations that still have NETGEAR DGN2200 devices deployed, especially security teams responsible for legacy network equipment, branch offices, home-office fleets, or unmanaged embedded devices.

Technical summary

The vulnerability is identified as an OS command injection issue in NETGEAR DGN2200 devices. The CISA KEV entry confirms it as a known exploited vulnerability and states the impacted product is end-of-life. Because no vendor remediation is provided in the supplied source corpus, the practical defensive response is removal, isolation, or replacement rather than patching.

Defensive priority

High. This is a known exploited vulnerability affecting an end-of-life product, so exposure should be treated as urgent and remediation should focus on disconnecting or replacing affected systems.

Recommended defensive actions

  • Inventory all NETGEAR DGN2200 devices and confirm whether any remain connected or reachable.
  • Follow CISA’s required action and disconnect impacted devices if they are still in use.
  • Replace end-of-life devices with supported hardware or a supported alternative.
  • Remove any unnecessary network exposure while migration is underway.
  • Review adjacent systems and network segments for signs of compromise if the device has been exposed to untrusted networks.

Evidence notes

The supplied source corpus includes the CISA Known Exploited Vulnerabilities record for CVE-2017-6334, which names NETGEAR DGN2200 devices, identifies the issue as an OS command injection vulnerability, marks it as known exploited, and states the impacted product is end-of-life and should be disconnected if still in use. The included official links point to the CVE record, NVD detail, and CISA KEV catalog.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-6334 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-6334

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-6334 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6334

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.