CVE-2016-10174

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
netgeard6100_firmware
-
netgeard7000_firmware
-
netgeard7800_firmware
-
netgearjnr1010v2_firmware
-
netgearjnr3300_firmware
-
netgearjwnr2010v5_firmware
-
netgearr2000_firmware
-
netgearr6100_firmware
-
netgearr6220_firmware
-
netgearr7500_firmware
-
netgearr7500v2_firmware
-
netgearwndr3700v4_firmware
-
netgearwndr3800_firmware
-
netgearwndr4300_firmware
-
netgearwndr4300v2_firmware
-
netgearwndr4500v3_firmware
-
netgearwndr4700_firmware
-
netgearwnr1000v2_firmware
-
netgearwnr1000v4_firmware
-
netgearwnr2000v3_firmware
-
netgearwnr2000v4_firmware
-
netgearwnr2000v5_firmware
-
netgearwnr2020_firmware
-
netgearwnr2050_firmware
-
netgearwnr2200_firmware
-
netgearwnr2500_firmware
-
netgearwnr614_firmware
-
netgearwnr618_firmware
-
𝑥
= Vulnerable software versions