CVE-2016-10174: NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability
The NETGEAR WNR2000v5 router contains a buffer overflow in the hiddenlangavi parameter when invoking the URL /apply.cgi?/langcheck.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
Other sources
The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10174?
CVE-2016-10174 is classified as a critical vulnerability due to its potential for remote code execution by unauthenticated attackers.
How can I fix CVE-2016-10174?
To mitigate CVE-2016-10174, users should update their NETGEAR WNR2000v5 router firmware to a version that is not vulnerable to this issue.
What products are affected by CVE-2016-10174?
CVE-2016-10174 specifically affects the NETGEAR WNR2000v5 router with firmware versions up to and including 1.0.0.34.
Can CVE-2016-10174 be exploited remotely?
Yes, CVE-2016-10174 can be exploited remotely by an unauthenticated attacker, allowing them to execute arbitrary code.
What is the nature of the vulnerability in CVE-2016-10174?
CVE-2016-10174 involves a buffer overflow vulnerability in the hidden_lang_avi parameter when accessing a specific URL on the router.