Skip to content
COOEY

EXPOSURES › CVE-2016-10174

CVE-2016-10174

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-10174 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

NETGEAR WNR2000v5 router buffer overflow allows remote code execution and is actively exploited in the wild.

The NETGEAR WNR2000v5 router contains a buffer overflow vulnerability that enables remote code execution, making it a critical risk for any network using this device. DIB organizations must ensure all such hardware is patched or replaced, as unpatched devices are frequently targeted by threat actors for lateral movement and data exfiltration. This failure highlights the ongoing risk of shipping and deploying unpatched consumer-grade hardware in enterprise environments.

Shame score — A known buffer overflow vulnerability in a widely deployed consumer router was left unpatched and is actively exploited in the wild, demonstrating severe negligence in patch management and supply chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.