EXPOSURES › CVE-2016-10174
CVE-2016-10174
HIGH ⌖ ON CISA KEV · EXPLOITEDNETGEAR WNR2000v5 router buffer overflow allows remote code execution and is actively exploited in the wild.
The NETGEAR WNR2000v5 router contains a buffer overflow vulnerability that enables remote code execution, making it a critical risk for any network using this device. DIB organizations must ensure all such hardware is patched or replaced, as unpatched devices are frequently targeted by threat actors for lateral movement and data exfiltration. This failure highlights the ongoing risk of shipping and deploying unpatched consumer-grade hardware in enterprise environments.
Shame score — A known buffer overflow vulnerability in a widely deployed consumer router was left unpatched and is actively exploited in the wild, demonstrating severe negligence in patch management and supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.