CVE-2016-1555 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 98.3% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 98.29% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | yes |
| Published | 2017-04-21 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | NETGEAR Multiple WAP Devices Command Injection Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | NETGEAR / Wireless Access Point (WAP) Devices |
| Ransomware use | none reported |
Affected (14)
| Vendor | Product |
|---|---|
| netgear | wn604 |
| netgear | wn604 firmware |
| netgear | wn802tv2 |
| netgear | wn802tv2 firmware |
| netgear | wnap320 |
| netgear | wnap320 firmware |
| netgear | wndap210v2 |
| netgear | wndap210v2 firmware |
| netgear | wndap350 |
| netgear | wndap350 firmware |
| netgear | wndap360 |
| netgear | wndap360 firmware |
| netgear | wndap660 |
| netgear | wndap660 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Netgear Devices - (Unauthenticated) Remote Command Execution (Metasploit) | 2018-11-27 |
References
- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2016/Feb/112
- https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic
- https://www.exploit-db.com/exploits/45909/
- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2016/Feb/112
- https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic
- https://www.exploit-db.com/exploits/45909/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1555
→ the Explorer · watch your stack · NVD