Junglewise Threat Intelligence

CVE-2016-10174: NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

CVE-2016-10174 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: NETGEAR WNR2000v5. Vendors: NETGEAR.

Executive brief

The NETGEAR WNR2000v5 router and several other models contain a buffer overflow in the hidden_lang_avi parameter when invoking the /apply.cgi?/lang_check.html URL. This vulnerability allows an unauthenticated remote attacker to execute arbitrary code.

Affected products

  • NETGEAR WNR2000v5
  • NETGEAR D6100
  • NETGEAR D7000
  • NETGEAR D7800
  • NETGEAR JNR1010v2
  • NETGEAR JNR3300
  • NETGEAR JWNR2010v5
  • NETGEAR R2000
  • NETGEAR R6100
  • NETGEAR R6220
  • NETGEAR R7500

Timeline

  • 2016-12-20: disclosed: Public disclosure via Seclists FD
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats