Executive brief
The NETGEAR WNR2000v5 router and several other models contain a buffer overflow in the hidden_lang_avi parameter when invoking the /apply.cgi?/lang_check.html URL. This vulnerability allows an unauthenticated remote attacker to execute arbitrary code.
Affected products
- NETGEAR WNR2000v5
- NETGEAR D6100
- NETGEAR D7000
- NETGEAR D7800
- NETGEAR JNR1010v2
- NETGEAR JNR3300
- NETGEAR JWNR2010v5
- NETGEAR R2000
- NETGEAR R6100
- NETGEAR R6220
- NETGEAR R7500
Timeline
- 2016-12-20: disclosed: Public disclosure via Seclists FD
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog