Skip to content
COOEY

EXPOSURES › CVE-2016-1555

CVE-2016-1555

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-1555 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

NETGEAR WAP devices allowed unauthenticated command injection via web forms, enabling arbitrary code execution.

NETGEAR wireless access points passed unauthenticated form input directly to the command-line interface, allowing attackers to execute arbitrary code. This is a critical failure for DIB organizations because it represents a severe, avoidable vulnerability in network infrastructure that could lead to complete device compromise and lateral movement. Organizations must ensure all network hardware is patched and monitored for known exploited vulnerabilities.

Shame score — A fundamental command injection flaw in widely deployed network hardware that was actively exploited in the wild, demonstrating severe negligence in patching and secure design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.