CVE-2016-1555
NETGEAR Multiple WAP Devices Command Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, y (5) boardDataWW.php en Netgear WN604 en versiones anteriores a 3.3.3 y WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360 y WNDAP660 en versiones anteriores a 3.5.5.0 permite a atacantes remotos ejecutar comandos arbitrarios.
Netgear WN604 versions before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 versions before 3.5.5.0 allow remote attackers to execute arbitrary commands.
Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-01-07 CVE Reserved
- 2016-02-26 CVE Published
- 2022-03-25 Exploited in Wild
- 2022-04-15 KEV Due Date
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-11-03 EPSS Updated
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html | Third Party Advisory | |
http://seclists.org/fulldisclosure/2016/Feb/112 | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/45909 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic | 2016-02-25 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | Wnap320 Firmware Search vendor "Netgear" for product "Wnap320 Firmware" | <= 3.0.5.0 Search vendor "Netgear" for product "Wnap320 Firmware" and version " <= 3.0.5.0" | - |
Affected
| in | Netgear Search vendor "Netgear" | Wnap320 Search vendor "Netgear" for product "Wnap320" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Wndap350 Firmware Search vendor "Netgear" for product "Wndap350 Firmware" | <= 3.0.5.0 Search vendor "Netgear" for product "Wndap350 Firmware" and version " <= 3.0.5.0" | - |
Affected
| in | Netgear Search vendor "Netgear" | Wndap350 Search vendor "Netgear" for product "Wndap350" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Wndap360 Firmware Search vendor "Netgear" for product "Wndap360 Firmware" | <= 3.0.5.0 Search vendor "Netgear" for product "Wndap360 Firmware" and version " <= 3.0.5.0" | - |
Affected
| in | Netgear Search vendor "Netgear" | Wndap360 Search vendor "Netgear" for product "Wndap360" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Wndap210v2 Firmware Search vendor "Netgear" for product "Wndap210v2 Firmware" | <= 3.0.5.0 Search vendor "Netgear" for product "Wndap210v2 Firmware" and version " <= 3.0.5.0" | - |
Affected
| in | Netgear Search vendor "Netgear" | Wndap210v2 Search vendor "Netgear" for product "Wndap210v2" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Wn604 Firmware Search vendor "Netgear" for product "Wn604 Firmware" | <= 3.3.2 Search vendor "Netgear" for product "Wn604 Firmware" and version " <= 3.3.2" | - |
Affected
| in | Netgear Search vendor "Netgear" | Wn604 Search vendor "Netgear" for product "Wn604" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Wndap660 Firmware Search vendor "Netgear" for product "Wndap660 Firmware" | <= 3.0.5.0 Search vendor "Netgear" for product "Wndap660 Firmware" and version " <= 3.0.5.0" | - |
Affected
| in | Netgear Search vendor "Netgear" | Wndap660 Search vendor "Netgear" for product "Wndap660" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Wn802tv2 Firmware Search vendor "Netgear" for product "Wn802tv2 Firmware" | <= 3.0.5.0 Search vendor "Netgear" for product "Wn802tv2 Firmware" and version " <= 3.0.5.0" | - |
Affected
| in | Netgear Search vendor "Netgear" | Wn802tv2 Search vendor "Netgear" for product "Wn802tv2" | - | - |
Safe
|