VulnerabilityAnalyzed
CVE-2016-1555
NETGEAR Multiple WAP Devices Command Injection Vulnerability
KEVCRITICAL 9.8EPSS 98.3%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 98.32% probability · 100th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-77
- Affected
- netgear/wnap320 firmware · netgear/wndap350 firmware · netgear/wndap360 firmware · netgear/wndap210v2 firmware · netgear/wn604 firmware · netgear/wndap660 firmware · netgear/wn802tv2 firmware
- Source
- cret@cert.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-1555
References
- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Feb/112Mailing List, Third Party Advisory
- https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organicPatch, Vendor Advisory
- https://www.exploit-db.com/exploits/45909/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Feb/112Mailing List, Third Party Advisory
- https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organicPatch, Vendor Advisory
- https://www.exploit-db.com/exploits/45909/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1555US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.