← Back to CVE List
Vulnerability Intelligence Report
NETGEAR Multiple WAP Devices Command Injection Vulnerability

CVE-2016-1555

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:98.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-77 ↗CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
netgear wnap320_firmware all
netgear wnap320 all
netgear wndap350_firmware all
netgear wndap350 all
netgear wndap360_firmware all
netgear wndap360 all
netgear wndap210v2_firmware all
netgear wndap210v2 all
netgear wn604_firmware all
netgear wn604 all
netgear wndap660_firmware all
netgear wndap660 all
netgear wn802tv2_firmware all
netgear wn802tv2 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
98.325%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT/CC · CERT · USA
Reserved2016-01-07T00:00:00
Published2017-04-21T15:00:00
Patch Date2016-02-24
Last Updated2025-10-21T23:55:42

LINK COPIED TO CLIPBOARD