// For flags

CVE-2016-1555

NETGEAR Multiple WAP Devices Command Injection Vulnerability

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

-
*SSVC
Descriptions

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, y (5) boardDataWW.php en Netgear WN604 en versiones anteriores a 3.3.3 y WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360 y WNDAP660 en versiones anteriores a 3.5.5.0 permite a atacantes remotos ejecutar comandos arbitrarios.

Netgear WN604 versions before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 versions before 3.5.5.0 allow remote attackers to execute arbitrary commands.

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-01-07 CVE Reserved
  • 2016-02-26 CVE Published
  • 2022-03-25 Exploited in Wild
  • 2022-04-15 KEV Due Date
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • 2024-11-03 EPSS Updated
CWE
  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netgear
Search vendor "Netgear"
Wnap320 Firmware
Search vendor "Netgear" for product "Wnap320 Firmware"
<= 3.0.5.0
Search vendor "Netgear" for product "Wnap320 Firmware" and version " <= 3.0.5.0"
-
Affected
in Netgear
Search vendor "Netgear"
Wnap320
Search vendor "Netgear" for product "Wnap320"
--
Safe
Netgear
Search vendor "Netgear"
Wndap350 Firmware
Search vendor "Netgear" for product "Wndap350 Firmware"
<= 3.0.5.0
Search vendor "Netgear" for product "Wndap350 Firmware" and version " <= 3.0.5.0"
-
Affected
in Netgear
Search vendor "Netgear"
Wndap350
Search vendor "Netgear" for product "Wndap350"
--
Safe
Netgear
Search vendor "Netgear"
Wndap360 Firmware
Search vendor "Netgear" for product "Wndap360 Firmware"
<= 3.0.5.0
Search vendor "Netgear" for product "Wndap360 Firmware" and version " <= 3.0.5.0"
-
Affected
in Netgear
Search vendor "Netgear"
Wndap360
Search vendor "Netgear" for product "Wndap360"
--
Safe
Netgear
Search vendor "Netgear"
Wndap210v2 Firmware
Search vendor "Netgear" for product "Wndap210v2 Firmware"
<= 3.0.5.0
Search vendor "Netgear" for product "Wndap210v2 Firmware" and version " <= 3.0.5.0"
-
Affected
in Netgear
Search vendor "Netgear"
Wndap210v2
Search vendor "Netgear" for product "Wndap210v2"
--
Safe
Netgear
Search vendor "Netgear"
Wn604 Firmware
Search vendor "Netgear" for product "Wn604 Firmware"
<= 3.3.2
Search vendor "Netgear" for product "Wn604 Firmware" and version " <= 3.3.2"
-
Affected
in Netgear
Search vendor "Netgear"
Wn604
Search vendor "Netgear" for product "Wn604"
--
Safe
Netgear
Search vendor "Netgear"
Wndap660 Firmware
Search vendor "Netgear" for product "Wndap660 Firmware"
<= 3.0.5.0
Search vendor "Netgear" for product "Wndap660 Firmware" and version " <= 3.0.5.0"
-
Affected
in Netgear
Search vendor "Netgear"
Wndap660
Search vendor "Netgear" for product "Wndap660"
--
Safe
Netgear
Search vendor "Netgear"
Wn802tv2 Firmware
Search vendor "Netgear" for product "Wn802tv2 Firmware"
<= 3.0.5.0
Search vendor "Netgear" for product "Wn802tv2 Firmware" and version " <= 3.0.5.0"
-
Affected
in Netgear
Search vendor "Netgear"
Wn802tv2
Search vendor "Netgear" for product "Wn802tv2"
--
Safe