CVE-2016-10116: Critical severity netgear arlo base station firmware vulnerability

Published Jan 4, 2017
·
Updated

NETGEAR Arlo base stations with firmware 1.7.56178 and earlier, Arlo Q devices with firmware 1.8.05551 and earlier, and Arlo Q Plus devices with firmware 1.8.16094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain access via a dictionary attack.

Affected Software

8 affected components
Netgear Arlo Base Station Firmware<=1.7.5_6178
Netgear Vmb30x0
Netgear Vmk3xx0
Netgear Vms3xx0
Netgear Arlo Q Camera Firmware<=1.8.0_5551
Netgear Vmc3040
Netgear Arlo Q Plus Camera Firmware<=1.8.1_6094
Netgear Vmc3040s

Event History

Jan 4, 2017
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2016-10116?

CVE-2016-10116 is considered a high severity vulnerability due to the ease of performing brute-force attacks on weak passwords.

2

How does CVE-2016-10116 affect Netgear Arlo devices?

CVE-2016-10116 affects several Netgear Arlo devices that use a predictable pattern for generating customized passwords, making them susceptible to unauthorized access.

3

How do I fix CVE-2016-10116?

To resolve CVE-2016-10116, update the affected Netgear Arlo devices to the latest firmware version that eliminates the use of predictable password patterns.

4

What versions of Arlo devices are vulnerable to CVE-2016-10116?

CVE-2016-10116 affects Netgear Arlo base stations with firmware versions 1.7.5_6178 and earlier, along with Arlo Q and Arlo Q Plus devices with specific earlier firmware versions.

5

Can I prevent CVE-2016-10116 by changing my password?

Changing the default password to a strong, unique password can mitigate the risk associated with CVE-2016-10116, but firmware updates are essential for full protection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203