Vulnerability threat dossier

CVE-2016-6277

netgeard6220

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

VTP deterministic threat59.5of 100 · CVSS excluded

VTP analyst assessment

Monitoring — no AI review currently required

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidenceUnknown
Public exploitation · VTP factKEV

Assessment

This CVE remains in monitoring. Its metadata and source evidence are available below. A new material report or relevant sensor finding can trigger an AI review.

Why it matters

The available facts and source references are listed below. No AI assessment has been recorded for this dossier.

Evidence

No validated baseline evidence scope is persisted for this CVE.

Uncertainties

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

A validated functional exploit or automated exploitation capability would materially change this assessment.

AI baseline history (0)
    Technical severityHIGHCVSS 8.8 · technical context
    Public exploitationKEVGlobal public evidence
    Exploit maturityPOCReliability not implied
    EPSS1.00100th percentile · prediction
    Evidence confidence90%Strongest independent active claim
    VelocitySTABLEMaterial events only
    First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
    Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
    01

    VTP deterministic assessment

    Why this matters

    1. 01

      CISA KEV lists this vulnerability as known to be exploited globally.

    2. 02

      A proof of concept is reported; functional reliability is not established.

    3. 03

      EPSS is 1.00; this is predictive context, not exploitation evidence.

    4. 04

      First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

    02

    Material change ledger

    What changed

    EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
    KEV ADDEDCISA KEV entry added
    03

    Claim provenance

    Evidence and source independence

    2publications detected
    2underlying evidence chains

    0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

    Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
    90%claim confidence
    PRIMARYcorpus:OPENVAS_NASL:84fac8c667854c85120d3ddaa1351b5aecec7db8ACTIVE
    04

    Event history

    Threat timeline

    1. 05:5103 Sept
      EXPLOIT TEMPLATE AVAILABLE

      Public exploit-oriented template available

      Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

    2. 00:0007 Mar
      KEV ADDED

      CISA KEV entry added

      CISA lists global known exploitation. This is not a VTP sensor observation.

    05

    Original publications

    Source record

    Exploit tooling coverage changed for 62 CVEs

    Greenbone Community Feed recorded exploit-tooling coverage changes for 62 CVEs in this pinned revision. 62 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

    CVE-2014-6444CVE-2015-3964CVE-2015-4694CVE-2015-5151CVE-2015-5472CVE-2015-6479CVE-2015-6940CVE-2015-7450CVE-2015-8103CVE-2015-8669CVE-2016-0476CVE-2016-0477CVE-2016-0478CVE-2016-0480CVE-2016-0481CVE-2016-0482CVE-2016-0484CVE-2016-0485CVE-2016-0486CVE-2016-0487CVE-2016-0488CVE-2016-0489CVE-2016-0490CVE-2016-0491CVE-2016-0492CVE-2016-1000141CVE-2016-10174CVE-2016-10175CVE-2016-10176CVE-2016-10372CVE-2016-1236CVE-2016-15044CVE-2016-15049CVE-2016-15055CVE-2016-2004CVE-2016-2042CVE-2016-2043CVE-2016-2044CVE-2016-2045CVE-2016-2230CVE-2016-2511CVE-2016-3737CVE-2016-5097CVE-2016-5098CVE-2016-5312CVE-2016-5563CVE-2016-5564CVE-2016-5565CVE-2016-5817CVE-2016-5843CVE-2016-6255CVE-2016-6277CVE-2016-6601CVE-2016-8339CVE-2016-9155CVE-2016-9835CVE-2017-1000028CVE-2017-1000029CVE-2017-1000030CVE-2025-34118CVE-2025-34119CVE-2025-34126
    Separate evidence group

    Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

    Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including

    CVE-2007-3010CVE-2016-6277CVE-2018-14558CVE-2019-14931CVE-2020-10987CVE-2021-36260CVE-2021-46422CVE-2022-26134CVE-2022-29464CVE-2022-30525CVE-2022-37055CVE-2023-1389CVE-2024-10914CVE-2024-29269CVE-2024-4577CVE-2025-10123CVE-2025-1974CVE-2025-55583
    Separate evidence group
    Original
    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score59.5vtp-threat-v1-public
    Public exploitation30 / 30
    EPSS prediction19.96 / 20
    Exploit availability7.5 / 15
    Source independence0 / 15
    Intelligence recency2 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    8.8 · HIGH
    Vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    CWE
    CWE-352
    CPE records
    22
    Deterministic history records
    20
    Primary technical reference
    07

    Raw observations

    First-party sensor records

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.