CVE-2016-6277Active Exploitation(netgear / d6220)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for netgear d6220 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-09-07. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-352

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • d6220
  • d6220_firmware
  • d6400
  • d6400_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
d6220d6220_firmwared6400d6400_firmwarer6250r6250_firmwarer6400r6400_firmwarer6700r6700_firmware

1 version affected across 22 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-18: 2Active Exploitation · 2026-02-18: 102-18
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2016-6277 — Connect-Surf-and-Smile-Limited Visit -- https://cti.loginsoft.com/ip/102.212.40.100 #Loginsoft #Cytellite #Cybersecurity #CVE20166277 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/NKqhUJDMrg

    Post summary

    Cytellite reports detection of CVE-2016-6277 but offers no detailed technical, exploitation, or mitigation information.

    0000033
    19 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2016-6277 — Connect-Surf-and-Smile-Limited Visit -- https://cti.loginsoft.com/ip/102.212.40.100 #Loginsoft #Cytellite #Cybersecurity #CVE20166277 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/L9D915HH0q

    Post summary

    Cytellite reports recent detection of activity targeting CVE-2016-6277, suggesting in-the-wild exploitation.

    0000031
    19 followersView on X
CPE platform detail22 entries

22 of 22 entries

PartVendorProductVersionTarget SWTarget HW
HWnetgeard6220---
OSnetgeard6220_firmware---
HWnetgeard6400---
OSnetgeard6400_firmware---
HWnetgearr6250---
OSnetgearr6250_firmware---
HWnetgearr6400---
OSnetgearr6400_firmware---
HWnetgearr6700---
OSnetgearr6700_firmware---
HWnetgearr6900---
OSnetgearr6900_firmware---
HWnetgearr7000---
OSnetgearr7000_firmware---
HWnetgearr7100lg---
OSnetgearr7100lg_firmware---
HWnetgearr7300dst---
OSnetgearr7300dst_firmware---
HWnetgearr7900---
OSnetgearr7900_firmware---
HWnetgearr8000---
OSnetgearr8000_firmware---

Explore more