peter bassill · operator
$ cve CVE-2016-1555 JSON

CVE-2016-1555 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 98.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS98.29% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-77
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2017-04-21
Last modified2026-06-17

CISA KEV

NameNETGEAR Multiple WAP Devices Command Injection Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productNETGEAR / Wireless Access Point (WAP) Devices
Ransomware usenone reported

Affected (14)

VendorProduct
netgearwn604
netgearwn604 firmware
netgearwn802tv2
netgearwn802tv2 firmware
netgearwnap320
netgearwnap320 firmware
netgearwndap210v2
netgearwndap210v2 firmware
netgearwndap350
netgearwndap350 firmware
netgearwndap360
netgearwndap360 firmware
netgearwndap660
netgearwndap660 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD