CVE-2016-1555: NETGEAR Multiple WAP Devices Command Injection Vulnerability
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
Other sources
Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NETGEAR WN604to a version that resolves this vulnerability.Fixed in 3.3.3 - Upgrade
Upgrade
NETGEAR WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, WNDAP660to a version that resolves this vulnerability.Fixed in 3.5.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1555?
CVE-2016-1555 has a high severity rating due to its remote command execution vulnerability.
How do I fix CVE-2016-1555?
To fix CVE-2016-1555, update the affected Netgear devices to firmware version 3.3.3 or later.
What devices are affected by CVE-2016-1555?
CVE-2016-1555 affects various Netgear Wireless Access Point devices, including WN604, WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660.
Can CVE-2016-1555 lead to full system compromise?
Yes, CVE-2016-1555 can allow remote attackers to execute arbitrary commands, potentially leading to full system compromise.
Is CVE-2016-1555 related to any other vulnerabilities?
CVE-2016-1555 is noted for being part of a broader category of remote command execution vulnerabilities in network devices.