MEDIUM · 4.3

CVE-2016-11055

Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 befor...

Vulnerability Description

Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 before 2017-01-11, JWNR2000Tv3 before 2017-01-11, JWNR2010v3 before 2017-01-11, PLW1000 before 2017-01-11, PLW1010 before 2017-01-11, WNR500 before 2017-01-11, WNR612v3 before 2017-01-11, N450 before 2017-01-11, and CG3000Dv2 before 2017-01-11.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
NetgearCm400 Firmware< 2017-01-11
NetgearCm400-
NetgearCm600 Firmware< 2017-01-11
NetgearCm600-
NetgearD1500 Firmware< 1.0.0.20
NetgearD1500-
NetgearD500 Firmware< 2017-01-11
NetgearD500-
NetgearDst6501 Firmware< 1.0.0.36
NetgearDst6501-
NetgearJnr1010 Firmware< 2017-01-11
NetgearJnr1010v1
NetgearJwnr2000T Firmware< 2017-01-11
NetgearJwnr2000Tv3
NetgearJwnr2010 Firmware< 2017-01-11
NetgearJwnr2010v3
NetgearPlw1000 Firmware< 1.0.0.22
NetgearPlw1000-
NetgearPlw1010 Firmware< 2017-01-11
NetgearPlw1010-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-11055?

CVE-2016-11055 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 befor...

How severe is CVE-2016-11055?

CVE-2016-11055 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-11055?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear Cm400 Firmware, Netgear Cm400, Netgear Cm600 Firmware, Netgear Cm600, Netgear D1500 Firmware.