Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-10174


The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.


Security Impact Summary

This vulnerability carries a CRITICAL severity rating with a CVSS v3.1 score of 9.8, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 56 products from netgear, from netgear, from netgear and 53 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2017, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2017-01-30T04:59:00.157

Last Modified

2025-10-22T00:15:48.580

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-120
  • Type: Secondary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear d6100_firmware - Yes
Hardware netgear d6100 - No
Operating System netgear d7000_firmware - Yes
Hardware netgear d7000 - No
Operating System netgear d7800_firmware - Yes
Hardware netgear d7800 - No
Operating System netgear jnr1010v2_firmware - Yes
Hardware netgear jnr1010v2 - No
Operating System netgear jnr3300_firmware - Yes
Hardware netgear jnr3300 - No
Operating System netgear jwnr2010v5_firmware - Yes
Hardware netgear jwnr2010v5 - No
Operating System netgear r2000_firmware - Yes
Hardware netgear r2000 - No
Operating System netgear r6100_firmware - Yes
Hardware netgear r6100 - No
Operating System netgear r6220_firmware - Yes
Hardware netgear r6220 - No
Operating System netgear r7500_firmware - Yes
Hardware netgear r7500 - No
Operating System netgear r7500v2_firmware - Yes
Hardware netgear r7500v2 - No
Operating System netgear wndr3700v4_firmware - Yes
Hardware netgear wndr3700v4 - No
Operating System netgear wndr3800_firmware - Yes
Hardware netgear wndr3800 - No
Operating System netgear wndr4300_firmware - Yes
Hardware netgear wndr4300 - No
Operating System netgear wndr4300v2_firmware - Yes
Hardware netgear wndr4300v2 - No
Operating System netgear wndr4500v3_firmware - Yes
Hardware netgear wndr4500v3 - No
Operating System netgear wndr4700_firmware - Yes
Hardware netgear wndr4700 - No
Operating System netgear wnr1000v2_firmware - Yes
Hardware netgear wnr1000v2 - No
Operating System netgear wnr1000v4_firmware - Yes
Hardware netgear wnr1000v4 - No
Operating System netgear wnr2000v3_firmware - Yes
Hardware netgear wnr2000v3 - No
Operating System netgear wnr2000v4_firmware - Yes
Hardware netgear wnr2000v4 - No
Operating System netgear wnr2000v5_firmware - Yes
Hardware netgear wnr2000v5 - No
Operating System netgear wnr2020_firmware - Yes
Hardware netgear wnr2020 - No
Operating System netgear wnr2050_firmware - Yes
Hardware netgear wnr2050 - No
Operating System netgear wnr2200_firmware - Yes
Hardware netgear wnr2200 - No
Operating System netgear wnr2500_firmware - Yes
Hardware netgear wnr2500 - No
Operating System netgear wnr614_firmware - Yes
Hardware netgear wnr614 - No
Operating System netgear wnr618_firmware - Yes
Hardware netgear wnr618 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For netgear's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.