{
  "id": "CVE-2016-6277",
  "url": "https://spydr.io/cve/CVE-2016-6277",
  "published": "2016-12-14T16:59:00.350Z",
  "modified": "2026-06-17T00:50:44.547Z",
  "score": 8.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.99803,
  "epss_percentile": 0.99957,
  "exploited": true,
  "kev": {
    "added": "2022-03-07",
    "due": "2022-09-07",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "NETGEAR Multiple Routers Remote Code Execution Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2016-6277"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "netgear"
  ],
  "products": [
    "netgear d6220 firmware",
    "netgear d6400 firmware",
    "netgear r6250 firmware",
    "netgear r6400 firmware",
    "netgear r6700 firmware",
    "netgear r6900 firmware",
    "netgear r7000 firmware",
    "netgear r7100lg firmware",
    "netgear r7300dst firmware",
    "netgear r7900 firmware",
    "netgear r8000 firmware"
  ],
  "cwes": [
    "CWE-352"
  ],
  "description": "NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 8.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://kb.netgear.com/000036386/CVE-2016-582384",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/155712/Netgear-R6400-Remote-Code-Execution.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/94819",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.sj-vs.net/a-temporary-fix-for-cert-vu582384-cwe-77-on-netgear-r7000-and-r6400-routers/",
      "tags": [
        "Broken Link",
        "Mitigation",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://kalypto.org/research/netgear-vulnerability-expanded/",
      "tags": [
        "Broken Link",
        "Exploit",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.exploit-db.com/exploits/40889/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.exploit-db.com/exploits/41598/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/582384",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-6277",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2016-6277",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
