CVE-2016-10174
NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability
Description
CVE-2016-10174 is a critical buffer overflow vulnerability affecting NETGEAR WNR2000v5 Router. The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. An attacker can exploit this flaw without authentication over the network. CISA has added this vulnerability to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 89.86% (99.6th percentile) indicates a significantly elevated exploitation probability.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| netgear | d6100 firmware | - |
| netgear | d7000 firmware | - |
| netgear | d7800 firmware | - |
| netgear | jnr1010v2 firmware | - |
| netgear | jnr3300 firmware | - |
| netgear | jwnr2010v5 firmware | - |
| netgear | r2000 firmware | - |
| netgear | r6100 firmware | - |
| netgear | r6220 firmware | - |
| netgear | r7500 firmware | - |
| netgear | r7500v2 firmware | - |
| netgear | wndr3700v4 firmware | - |
| netgear | wndr3800 firmware | - |
| netgear | wndr4300 firmware | - |
| netgear | wndr4300v2 firmware | - |
| netgear | wndr4500v3 firmware | - |
| netgear | wndr4700 firmware | - |
| netgear | wnr1000v2 firmware | - |
| netgear | wnr1000v4 firmware | - |
| netgear | wnr2000v3 firmware | - |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability(Vendor Advisory)
- http://seclists.org/fulldisclosure/2016/Dec/72(Exploit, Mailing List, Third Party Advisory, VDB Entry)
- http://www.securityfocus.com/bid/95867(Broken Link, Third Party Advisory, VDB Entry)
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt(Exploit, Technical Description, Third Party Advisory)
- https://www.exploit-db.com/exploits/40949/(Exploit, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/41719/(Exploit, Third Party Advisory, VDB Entry)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-10174(US Government Resource)
Weakness Type
CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Classic Buffer Overflow is a vulnerability that occurs when a program copies data to a buffer without first checking that the data fits within the buffer's allocated size. This typically happens when functions like strcpy(), gets(), sprintf(), or memcpy() are used without proper bounds checking. In the case of CVE-2016-10174, this weakness allows attackers to compromise NETGEAR WNR2000v5 Router systems.
Learn more: CWE-120 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Impact Analysis
CVE-2016-10174 carries a CVSS 3.1 base score of 9.8 (CRITICAL), reflecting the serious risk it poses to affected environments. Successful exploitation can lead to complete compromise of data confidentiality, full system integrity compromise, and complete denial of service. The attack vector is network-based with low complexity, meaning exploitation is straightforward and can be reliably repeated. Organizations running NETGEAR WNR2000v5 Router face tangible risk of unauthorized access, data breaches, and operational disruption if this vulnerability remains unpatched.
Exploit Maturity
CVE-2016-10174 is listed in the CISA Known Exploited Vulnerabilities catalog with a remediation deadline of 2022-04-15, confirming that real-world exploitation has been observed. The EPSS score of 89.86% (99.6th percentile) places this vulnerability among those most likely to be exploited. Public exploit code is available in vulnerability databases, lowering the barrier for attackers and increasing the urgency of remediation.
Remediation
- Apply updates per vendor instructions. This is the CISA-mandated remediation action and should be prioritized immediately.
- If patches cannot be applied immediately, restrict network access to the affected WNR2000v5 Router management interfaces to only trusted administrative networks using firewall rules or access control lists.
- Monitor vendor security advisories for additional updates and ensure a patch management process is in place for timely deployment.
- Conduct a thorough review of affected systems for signs of prior compromise, including unexpected user accounts, modified configurations, and unusual network activity.
- Implement defense-in-depth measures including network segmentation, intrusion detection systems, and continuous security monitoring for the affected infrastructure.
Technical Details
CVE-2016-10174 is exploitable remotely over the network without any prior authentication. The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. The attack complexity is rated low, meaning no specialized conditions or preparation are needed beyond network access to the target. The scope is unchanged, meaning the impact is confined to the vulnerable component. The CVSS 3.1 base score of 9.8 reflects the combination of these factors and the potential for significant damage to affected systems.
Frequently Asked Questions
Is CVE-2016-10174 being actively exploited?
Yes. CISA has confirmed active exploitation by adding CVE-2016-10174 to the Known Exploited Vulnerabilities catalog. The EPSS score of 89.86% (99.6th percentile) further indicates high exploitation likelihood.
What products are affected by CVE-2016-10174?
CVE-2016-10174 affects NETGEAR WNR2000v5 Router. Specifically, affected products include netgear d6100 firmware, netgear d7000 firmware, netgear d7800 firmware, netgear jnr1010v2 firmware, netgear jnr3300 firmware, and others.
How do I fix CVE-2016-10174?
Apply updates per vendor instructions. Ensure your systems are updated to the latest patched version. If immediate patching is not feasible, restrict network access to the affected system's management interfaces.
How severe is CVE-2016-10174?
CVE-2016-10174 has a CVSS 3.1 score of 9.8 (CRITICAL). This is a critical vulnerability that should be remediated with the highest priority. The vulnerability enables unauthenticated remote attackers to potentially compromise affected WNR2000v5 Router systems.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.