CVE-2016-1555: NETGEAR Multiple WAP Devices Command Injection Vulnerability

Published Apr 21, 2017
·
Updated

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

Other sources

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

CISA

Affected Software

29 affected components
Netgear Wireless Access Point (WAP) Devices
All of the following
Netgear Wnap320 Firmware<=3.0.5.0
Netgear WNAP320
All of the following
Netgear Wndap350 Firmware<=3.0.5.0
Netgear WNDAP350
All of the following
Netgear Wndap360 Firmware<=3.0.5.0
Netgear WNDAP360
All of the following
Netgear Wndap210v2 Firmware<=3.0.5.0
Netgear Wndap210v2
All of the following
Netgear Wn604 Firmware<=3.3.2
Netgear WN604
All of the following
Netgear Wndap660 Firmware<=3.0.5.0
Netgear WNDAP660
All of the following
Netgear Wn802tv2 Firmware<=3.0.5.0
Netgear WN802Tv2
Netgear Wnap320 Firmware<=3.0.5.0
Netgear WNAP320
Netgear Wndap350 Firmware<=3.0.5.0
Netgear WNDAP350
Netgear Wndap360 Firmware<=3.0.5.0
Netgear WNDAP360
Netgear Wndap210v2 Firmware<=3.0.5.0
Netgear Wndap210v2
Netgear Wn604 Firmware<=3.3.2
Netgear WN604
Netgear Wndap660 Firmware<=3.0.5.0
Netgear WNDAP660
Netgear Wn802tv2 Firmware<=3.0.5.0
Netgear WN802Tv2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade NETGEAR WN604 to a version that resolves this vulnerability.

    Fixed in 3.3.3
  2. Upgrade

    Upgrade NETGEAR WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, WNDAP660 to a version that resolves this vulnerability.

    Fixed in 3.5.5.0

Event History

Apr 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 25, 2022
Known Exploited
via CISA·12:00 AM
Mar 1, 58274
Event
via NVD·10:42 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-1555?

CVE-2016-1555 has a high severity rating due to its remote command execution vulnerability.

2

How do I fix CVE-2016-1555?

To fix CVE-2016-1555, update the affected Netgear devices to firmware version 3.3.3 or later.

3

What devices are affected by CVE-2016-1555?

CVE-2016-1555 affects various Netgear Wireless Access Point devices, including WN604, WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660.

4

Can CVE-2016-1555 lead to full system compromise?

Yes, CVE-2016-1555 can allow remote attackers to execute arbitrary commands, potentially leading to full system compromise.

5

Is CVE-2016-1555 related to any other vulnerabilities?

CVE-2016-1555 is noted for being part of a broader category of remote command execution vulnerabilities in network devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203