CRITICAL · 9.8

CVE-2016-10174

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated ...

Vulnerability Description

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NetgearD6100 Firmware-
NetgearD6100-
NetgearD7000 Firmware-
NetgearD7000-
NetgearD7800 Firmware-
NetgearD7800-
NetgearJnr1010V2 Firmware-
NetgearJnr1010V2-
NetgearJnr3300 Firmware-
NetgearJnr3300-
NetgearJwnr2010V5 Firmware-
NetgearJwnr2010V5-
NetgearR2000 Firmware-
NetgearR2000-
NetgearR6100 Firmware-
NetgearR6100-
NetgearR6220 Firmware-
NetgearR6220-
NetgearR7500 Firmware-
NetgearR7500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-10174?

CVE-2016-10174 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated ...

How severe is CVE-2016-10174?

CVE-2016-10174 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-10174?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear D6100 Firmware, Netgear D6100, Netgear D7000 Firmware, Netgear D7000, Netgear D7800 Firmware.