First published: Fri Apr 21 2017(Updated: )
Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR WNAP320 firmware | <=3.0.5.0 | |
Netgear WNAP320 firmware | ||
Netgear WNDAP350 Firmware | <=3.0.5.0 | |
NETGEAR WNDAP350 | ||
NETGEAR WNDAP360 | <=3.0.5.0 | |
NETGEAR WNDAP360 firmware | ||
Netgear WNDAP210v2 | <=3.0.5.0 | |
Netgear WNDAP210v2 Firmware | ||
NETGEAR WN604 firmware | <=3.3.2 | |
Netgear WN604 | ||
NETGEAR WND930 firmware | <=2.0.4 | |
NETGEAR WND930 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1556 is classified as a medium severity vulnerability due to information disclosure risks.
To fix CVE-2016-1556, update the firmware of affected Netgear devices to the latest version: WN604 to at least 3.3.3, WNAP210, WNAP320, WNDAP350, and WNDAP360 to at least 3.5.5.0, and WND930 to at least 2.0.11.
CVE-2016-1556 affects Netgear WN604, WNAP210, WNAP320, WNDAP350, WNDAP360, and WND930 devices with specific firmware versions.
CVE-2016-1556 is an information disclosure vulnerability that allows unauthorized users to access sensitive data.
You can check if your device is vulnerable to CVE-2016-1556 by verifying the firmware version against the affected versions listed in the CVE description.