10

CVE-2016-10174

Warning
Exploit

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

Data is provided by the National Vulnerability Database (NVD)
NetgearD6100 Firmware Version-
   NetgearD6100 Version-
NetgearD7000 Firmware Version-
   NetgearD7000 Version-
NetgearD7800 Firmware Version-
   NetgearD7800 Version-
NetgearJnr1010v2 Firmware Version-
   NetgearJnr1010v2 Version-
NetgearJnr3300 Firmware Version-
   NetgearJnr3300 Version-
NetgearJwnr2010v5 Firmware Version-
   NetgearJwnr2010v5 Version-
NetgearR2000 Firmware Version-
   NetgearR2000 Version-
NetgearR6100 Firmware Version-
   NetgearR6100 Version-
NetgearR6220 Firmware Version-
   NetgearR6220 Version-
NetgearR7500 Firmware Version-
   NetgearR7500 Version-
NetgearR7500v2 Firmware Version-
   NetgearR7500v2 Version-
NetgearWndr3700v4 Firmware Version-
   NetgearWndr3700v4 Version-
NetgearWndr3800 Firmware Version-
   NetgearWndr3800 Version-
NetgearWndr4300 Firmware Version-
   NetgearWndr4300 Version-
NetgearWndr4300v2 Firmware Version-
   NetgearWndr4300v2 Version-
NetgearWndr4500v3 Firmware Version-
   NetgearWndr4500v3 Version-
NetgearWndr4700 Firmware Version-
   NetgearWndr4700 Version-
NetgearWnr1000v2 Firmware Version-
   NetgearWnr1000v2 Version-
NetgearWnr1000v4 Firmware Version-
   NetgearWnr1000v4 Version-
NetgearWnr2000v3 Firmware Version-
   NetgearWnr2000v3 Version-
NetgearWnr2000v4 Firmware Version-
   NetgearWnr2000v4 Version-
NetgearWnr2000v5 Firmware Version-
   NetgearWnr2000v5 Version-
NetgearWnr2020 Firmware Version-
   NetgearWnr2020 Version-
NetgearWnr2050 Firmware Version-
   NetgearWnr2050 Version-
NetgearWnr2200 Firmware Version-
   NetgearWnr2200 Version-
NetgearWnr2500 Firmware Version-
   NetgearWnr2500 Version-
NetgearWnr614 Firmware Version-
   NetgearWnr614 Version-
NetgearWnr618 Firmware Version-
   NetgearWnr618 Version-

25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

Vulnerability

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 91.84% 0.996
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.