CVE-2016-10174
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 83% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-120
מוצרים מושפעים
netgear: d6100 firmware; netgear: d6100; netgear: d7000 firmware; netgear: d7000; netgear: d7800 firmware; netgear: d7800; netgear: jnr1010v2 firmware; netgear: jnr1010v2; netgear: jnr3300 firmware; netgear: jnr3300; netgear: jwnr2010v5 firmware; netgear: jwnr2010v5; netgear: r2000 firmware; netgear: r2000; netgear: r6100 firmware
קישורים
- http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-S… Vendor Advisory
- http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-S… Vendor Advisory
- http://seclists.org/fulldisclosure/2016/Dec/72 ExploitMailing ListThird Party AdvisoryVDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000… ExploitTechnical DescriptionThird Party Advisory
- https://www.exploit-db.com/exploits/40949/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41719/ ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Dec/72 ExploitMailing ListThird Party AdvisoryVDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000… ExploitTechnical DescriptionThird Party Advisory
- https://www.exploit-db.com/exploits/40949/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41719/ ExploitThird Party AdvisoryVDB Entry