VulnerabilityAnalyzed
CVE-2016-10174
NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability
KEVCRITICAL 9.8EPSS 83.5%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 83.45% probability · 100th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-120
- Affected
- netgear/d6100 firmware · netgear/d7000 firmware · netgear/d7800 firmware · netgear/jnr1010v2 firmware · netgear/jnr3300 firmware · netgear/jwnr2010v5 firmware · netgear/r2000 firmware · netgear/r6100 firmware · netgear/r6220 firmware · netgear/r7500 firmware · netgear/r7500v2 firmware · netgear/wndr3700v4 firmware · netgear/wndr3800 firmware · netgear/wndr4300 firmware · netgear/wndr4300v2 firmware · netgear/wndr4500v3 firmware · netgear/wndr4700 firmware · netgear/wnr1000v2 firmware · netgear/wnr1000v4 firmware · netgear/wnr2000v3 firmware · +8 more
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-10174
References
- http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-VulnerabilityVendor Advisory
- http://seclists.org/fulldisclosure/2016/Dec/72Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95867Broken Link, Third Party Advisory, VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txtExploit, Technical Description, Third Party Advisory
- https://www.exploit-db.com/exploits/40949/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41719/Exploit, Third Party Advisory, VDB Entry
- http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-VulnerabilityVendor Advisory
- http://seclists.org/fulldisclosure/2016/Dec/72Exploit, Mailing List, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95867Broken Link, Third Party Advisory, VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txtExploit, Technical Description, Third Party Advisory
- https://www.exploit-db.com/exploits/40949/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41719/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-10174US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.