Junglewise Threat Intelligence

CVE-2016-1555: NETGEAR Multiple WAP Devices Command Injection Vulnerability

CVE-2016-1555 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Vendors: NETGEAR.

Executive brief

Multiple NETGEAR Wireless Access Point devices are vulnerable to command injection via several PHP scripts (boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php, and boardDataWW.php). Unauthenticated remote attackers can execute arbitrary commands by passing malicious form input directly to the command-line interface.

Affected products

  • Netgear WN604 before 3.3.3
  • Netgear WN802Tv2 before 3.5.5.0
  • Netgear WNAP210v2 before 3.5.5.0
  • Netgear WNAP320 before 3.5.5.0
  • Netgear WNDAP350 before 3.5.5.0
  • Netgear WNDAP360 before 3.5.5.0
  • Netgear WNDAP660 before 3.5.5.0

Timeline

  • 2016-02-25: disclosed: Public disclosure via Seclists and Packet Storm Security
  • 2017-04-21: advisory: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog