CVE-2016-1555
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- NETGEAR Multiple WAP Devices Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 98% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-77
מוצרים מושפעים
netgear: wnap320 firmware; netgear: wnap320; netgear: wndap350 firmware; netgear: wndap350; netgear: wndap360 firmware; netgear: wndap360; netgear: wndap210v2 firmware; netgear: wndap210v2; netgear: wn604 firmware; netgear: wn604; netgear: wndap660 firmware; netgear: wndap660; netgear: wn802tv2 firmware; netgear: wn802tv2
קישורים
- https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic PatchVendor Advisory
- https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic PatchVendor Advisory
- https://www.exploit-db.com/exploits/45909/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/45909/ ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-I… Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Feb/112 Mailing ListThird Party Advisory
- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-I… Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Feb/112 Mailing ListThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource