PatchSiren cyber security CVE debrief
CVE-2017-6334 NETGEAR CVE debrief
CVE-2017-6334 is an OS command injection vulnerability affecting NETGEAR DGN2200 devices. CISA lists it in the Known Exploited Vulnerabilities catalog, which indicates known exploitation and raises the urgency for defenders. CISA’s noted required action is to disconnect the impacted product if it is still in use, because the product is end-of-life.
- Vendor
- NETGEAR
- Product
- DGN2200 Devices
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-03-25
- Original CVE updated
- 2022-03-25
- Advisory published
- 2022-03-25
- Advisory updated
- 2022-03-25
Who should care
Organizations that still have NETGEAR DGN2200 devices deployed, especially security teams responsible for legacy network equipment, branch offices, home-office fleets, or unmanaged embedded devices.
Technical summary
The vulnerability is identified as an OS command injection issue in NETGEAR DGN2200 devices. The CISA KEV entry confirms it as a known exploited vulnerability and states the impacted product is end-of-life. Because no vendor remediation is provided in the supplied source corpus, the practical defensive response is removal, isolation, or replacement rather than patching.
Defensive priority
High. This is a known exploited vulnerability affecting an end-of-life product, so exposure should be treated as urgent and remediation should focus on disconnecting or replacing affected systems.
Recommended defensive actions
- Inventory all NETGEAR DGN2200 devices and confirm whether any remain connected or reachable.
- Follow CISA’s required action and disconnect impacted devices if they are still in use.
- Replace end-of-life devices with supported hardware or a supported alternative.
- Remove any unnecessary network exposure while migration is underway.
- Review adjacent systems and network segments for signs of compromise if the device has been exposed to untrusted networks.
Evidence notes
The supplied source corpus includes the CISA Known Exploited Vulnerabilities record for CVE-2017-6334, which names NETGEAR DGN2200 devices, identifies the issue as an OS command injection vulnerability, marks it as known exploited, and states the impacted product is end-of-life and should be disconnected if still in use. The included official links point to the CVE record, NVD detail, and CISA KEV catalog.
Official resources
-
CVE-2017-6334 CVE record
CVE.org
-
CVE-2017-6334 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - The impacted product is end-of-life and should be disconnected if still in use.
-
Source item URL
cisa_kev
CVE published and modified on 2022-03-25 in the supplied timeline. CISA’s KEV entry in the supplied source is also dated 2022-03-25, with a remediation due date of 2022-04-15.