First published: Mon Jan 30 2017(Updated: )
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR WNR2000v5 firmware | <=1.0.0.34 | |
NETGEAR WNR2000v5 firmware | ||
NETGEAR WNR2000v5 firmware | ||
All of | ||
NETGEAR D6100 firmware | ||
NETGEAR D6100 firmware | ||
All of | ||
NETGEAR D7000v1 firmware | ||
NETGEAR D7000 firmware | ||
All of | ||
NETGEAR D7800 | ||
NETGEAR D7800 Firmware | ||
All of | ||
NETGEAR JNR1010v2 firmware | ||
NETGEAR JNR1010v2 firmware | ||
All of | ||
NETGEAR JNR3300 Firmware | ||
NETGEAR JNR3300 Firmware | ||
All of | ||
NETGEAR JWNR2010v5 | ||
NETGEAR JWNR2010v5 firmware | ||
All of | ||
NETGEAR R2000 firmware | ||
NETGEAR R2000 firmware | ||
All of | ||
NETGEAR R6100 firmware | ||
NETGEAR R6100 firmware | ||
All of | ||
NETGEAR R6220 firmware | ||
NETGEAR R6220 firmware | ||
All of | ||
NETGEAR R7500v2 firmware | ||
NETGEAR R7500v2 firmware | ||
All of | ||
NETGEAR R7500v2 firmware | ||
NETGEAR Nighthawk R7500 | ||
All of | ||
NETGEAR WNDR3700v4 Firmware | ||
NETGEAR WNDR3700v4 Firmware | ||
All of | ||
NETGEAR WNDR3800 Firmware | ||
NETGEAR WNDR3800 Firmware | ||
All of | ||
NETGEAR WNDR4300v2 firmware | ||
NETGEAR wndr4300v2 | ||
All of | ||
NETGEAR WNDR4300v2 | ||
NETGEAR WNDR4300v2 firmware | ||
All of | ||
NETGEAR WNDR4500v3 Firmware | ||
NETGEAR WNDR4500v3 Firmware | ||
All of | ||
NETGEAR WNDR4700 Firmware | ||
NETGEAR WNDR4700 Firmware | ||
All of | ||
NETGEAR WNR1000 firmware | ||
NETGEAR WNR1000v2 Firmware | ||
All of | ||
NETGEAR WNR1000 v4 | ||
NETGEAR WNR1000 firmware | ||
All of | ||
NETGEAR WNR2000v3 firmware | ||
NETGEAR WNR2000v3 firmware | ||
All of | ||
Netgear WNR2000v4 Firmware | ||
Netgear WNR2000v4 | ||
All of | ||
NETGEAR WNR2000v5 firmware | ||
NETGEAR WNR2000v5 firmware | ||
All of | ||
NETGEAR WNR2020 Firmware | ||
NETGEAR WNR2020 Firmware | ||
All of | ||
NETGEAR WNR2050 Firmware | ||
NETGEAR WNR2050 Firmware | ||
All of | ||
NETGEAR WNR2200 Firmware | ||
NETGEAR WNR2200 Firmware | ||
All of | ||
NETGEAR WNR2500 Firmware | ||
NETGEAR WNR2500 Firmware | ||
All of | ||
NETGEAR WGR614 firmware | ||
Netgear WNR614 | ||
All of | ||
NETGEAR WNR618 Firmware | ||
NETGEAR WNR618 Firmware | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
All of | ||
http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10174 is classified as a critical vulnerability due to its potential for remote code execution by unauthenticated attackers.
To mitigate CVE-2016-10174, users should update their NETGEAR WNR2000v5 router firmware to a version that is not vulnerable to this issue.
CVE-2016-10174 specifically affects the NETGEAR WNR2000v5 router with firmware versions up to and including 1.0.0.34.
Yes, CVE-2016-10174 can be exploited remotely by an unauthenticated attacker, allowing them to execute arbitrary code.
CVE-2016-10174 involves a buffer overflow vulnerability in the hidden_lang_avi parameter when accessing a specific URL on the router.