Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-1555


(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.


Published

2017-04-21T15:59:00.333

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear wnap320_firmware ≤ 3.0.5.0 Yes
Hardware netgear wnap320 - No
Operating System netgear wndap350_firmware ≤ 3.0.5.0 Yes
Hardware netgear wndap350 - No
Operating System netgear wndap360_firmware ≤ 3.0.5.0 Yes
Hardware netgear wndap360 - No
Operating System netgear wndap210v2_firmware ≤ 3.0.5.0 Yes
Hardware netgear wndap210v2 - No
Operating System netgear wn604_firmware ≤ 3.3.2 Yes
Hardware netgear wn604 - No
Operating System netgear wndap660_firmware ≤ 3.0.5.0 Yes
Hardware netgear wndap660 - No
Operating System netgear wn802tv2_firmware ≤ 3.0.5.0 Yes
Hardware netgear wn802tv2 - No

References