S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2016-6277 Scanner

CVE-2016-6277 scanner - Command Injection vulnerability in Multiple NETGEAR Routers

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2
Times Used
by S4E users
2
Assets Scanned
domains & IPs
2
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2016-6277
8.8
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

The NETGEAR routers are a popular choice for individual and business consumers alike, providing reliable and high-speed connectivity to the internet. These routers are used primarily for accessing the internet, managing network traffic and protecting sensitive data of end-users. With a secure setup, these routers allow easy access to online resources such as streaming services, online gaming platforms, and social media websites, while ensuring users' personal information stays protected.

However, a vulnerability identified as CVE-2016-6277 puts these routers and their users at risk. This vulnerability, present in models including R6250, R6400, R6700, R6900, R7000, R7100LG, R7300DST, R7900, R8000, D6220, D6400, D7000 and potentially other devices, enables remote hackers to execute arbitrary commands via shell metacharacters present in the path information to cgi-bin/.

Exploitation of CVE-2016-6277 vulnerability can lead to penetration of private and sensitive areas within these routers, facilitating unauthorized access for cybercriminals and malicious activities such as data theft, modification, and destruction. The worst-case scenarios include remote control over the router, exploitation, and hacking of connected devices within the network, and even the creation of a botnet that may allow attackers to launch DDoS (Distributed Denial of Service) attacks.

Thanks to the pro features of the s4e.io platform, it's easy to learn about vulnerabilities in your digital assets. By keeping abreast of the latest threats and being proactive in adopting security measures, individuals and businesses can safeguard their digital assets from vulnerabilities such as CVE-2016-6277 and other security risks.

 

REFERENCES

Solution Advice

Here are some precautions that users can adopt in order to protect their routers from this vulnerability.

  • Regular firmware updates from the manufacturer: Device manufacturers typically release regular firmware updates that include security patches to keep devices secure from the latest threats.
  • Limit access to the router's admin panel: It is advisable to limit admin panel access to trusted IP addresses only, so as to reduce the risk of unauthorized access to the router.
  • Change default usernames and passwords: Changing default usernames and passwords creates an additional layer of security that makes it difficult for hackers to access routers.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-6277 scanner - Command Injection vulnerability in Multiple NETGEAR Routers S4E