CVE-2016-10174
netgear d6100 firmware, netgear d7000 firmware, netgear d7800 firmware
Published 30 Jan 2017 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 Mar 2022, with a remediation deadline of 15 Apr 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
References
- kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability · Vendor Advisory
- seclists.org/fulldisclosure/2016/Dec/72 · Exploit, Mailing List, Third Party Advisory
- www.securityfocus.com/bid/95867 · Broken Link, Third Party Advisory, VDB Entry
- raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt · Exploit, Technical Description, Third Party Advisory
- www.exploit-db.com/exploits/40949/ · Exploit, Third Party Advisory, VDB Entry
- www.exploit-db.com/exploits/41719/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-10174 · US Government Resource