CVE-2016-10174

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
30/01/2017
Last modified:
22/10/2025

Description

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:d6100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:d6100:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:d7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:d7000:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:d7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:d7800:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:jnr1010v2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:jnr1010v2:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:jnr3300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:jnr3300:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:jwnr2010v5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:jwnr2010v5:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r2000:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6100_firmware:-:*:*:*:*:*:*:*