CVE-2016-10174
Last modified
CVE-2016-10174 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.. CISA has confirmed active exploitation in the wild. EPSS estimates a 83.45% chance of exploitation in the next 30 days.
Description
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netgear | D6100 Firmware | All versions |
| Netgear | D7000 Firmware | All versions |
| Netgear | D7800 Firmware | All versions |
| Netgear | Jnr1010v2 Firmware | All versions |
| Netgear | Jnr3300 Firmware | All versions |
| Netgear | Jwnr2010v5 Firmware | All versions |
| Netgear | R2000 Firmware | All versions |
| Netgear | R6100 Firmware | All versions |
| Netgear | R6220 Firmware | All versions |
| Netgear | R7500 Firmware | All versions |
| Netgear | R7500v2 Firmware | All versions |
| Netgear | Wndr3700v4 Firmware | All versions |
| Netgear | Wndr3800 Firmware | All versions |
| Netgear | Wndr4300 Firmware | All versions |
| Netgear | Wndr4300v2 Firmware | All versions |
| Netgear | Wndr4500v3 Firmware | All versions |
| Netgear | Wndr4700 Firmware | All versions |
| Netgear | Wnr1000v2 Firmware | All versions |
| Netgear | Wnr1000v4 Firmware | All versions |
| Netgear | Wnr2000v3 Firmware | All versions |
| Netgear | Wnr2000v4 Firmware | All versions |
| Netgear | Wnr2000v5 Firmware | All versions |
| Netgear | Wnr2020 Firmware | All versions |
| Netgear | Wnr2050 Firmware | All versions |
| Netgear | Wnr2200 Firmware | All versions |
| Netgear | Wnr2500 Firmware | All versions |
| Netgear | Wnr614 Firmware | All versions |
| Netgear | Wnr618 Firmware | All versions |
References
- https://seclists.org/fulldisclosure/2016/Dec/72Exploit, Mailing List, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/95867Broken Link, Third Party Advisory, VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txtExploit, Technical Description, Third Party Advisory
- https://www.exploit-db.com/exploits/40949/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41719/Exploit, Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2016/Dec/72Exploit, Mailing List, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/95867Broken Link, Third Party Advisory, VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txtExploit, Technical Description, Third Party Advisory
- https://www.exploit-db.com/exploits/40949/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41719/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-10174US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2016-10174?
How severe is CVE-2016-10174?
How do I fix CVE-2016-10174?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10169The read_code function in read_words.c in Wavpack before 5.1…
- CVE-2016-1017Use-after-free vulnerability in the LoadVars.decode function…8.8
- CVE-2016-10170The WriteCaffHeader function in cli/caff.c in Wavpack before…
- CVE-2016-10171The unreorder_channels function in cli/wvunpack.c in Wavpack…
- CVE-2016-10172The read_new_config_info function in open_utils.c in Wavpack…
- CVE-2016-10173Directory traversal vulnerability in the minitar before 0.6 …
- CVE-2016-10175The NETGEAR WNR2000v5 router leaks its serial number when pe…
- CVE-2016-10176The NETGEAR WNR2000v5 router allows an administrator to perf…
- CVE-2016-10177An issue was discovered on the D-Link DWR-932B router. Undoc…9.8
- CVE-2016-10178An issue was discovered on the D-Link DWR-932B router. HELOD…9.8
- CVE-2016-10179An issue was discovered on the D-Link DWR-932B router. There…7.5
- CVE-2016-1018Stack-based buffer overflow in Adobe Flash Player before 18.…8.8
Are you affected by CVE-2016-10174?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
