Netgear D6400
cpe:2.3:h:netgear:d6400:*:*:*:*:*:*:*, +1 more
- 1.0.0.114
A critical OS command injection vulnerability has been identified in the Netgear D6400 router, specifically in version 1.0.0.114. The issue arises in the diag.cgi file, where the host_name argument can be manipulated to execute arbitrary OS commands. This vulnerability can be exploited remotely and affects products that are no longer supported by the manufacturer.
Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.
To reproduce this vulnerability, send a crafted request to the router's diag.cgi file, manipulating the host_name argument. This can be done remotely, targeting the Netgear D6400 router running firmware version 1.0.0.114.
Users are advised to replace the affected component with an alternative, as this vulnerability affects an unsupported product.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.