ZeroHour

CVE-2016-10174

KEV PoC ×4large

Unauthenticated Buffer Overflow RCE in NETGEAR WNR2000v5 Router

CISA: NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
83%p100
Published
()
KEV added
AI analysis

The NETGEAR WNR2000v5 router contains a buffer overflow (CWE-120) in the hidden_lang_avi parameter processed by the /apply.cgi?/lang_check.html language-check endpoint. An unauthenticated attacker can send an HTTP request with an oversized hidden_lang_avi value to this URL, overflowing a fixed-size buffer and overwriting memory. Successful exploitation yields pre-authentication remote code execution and full compromise of the device (CVSS 3.1 9.8: network vector, low complexity, no privileges or user interaction, high confidentiality/integrity/availability impact). CISA's affected list names the WNR2000v5 router specifically, while the NVD CPE associations additionally cover other NETGEAR firmware products (D6100, D7000, D7800, JNR1010v2, JNR3300, JWNR2010v5, R2000, R6100, R6220, R7500, R7500v2, WNDR3700v4). The flaw is under active exploitation: it was added to the CISA Known Exploited Vulnerabilities catalog on 2022-03-25 (ransomware use unknown per CISA), EPSS assigns an 83.5% probability of exploitation within 30 days (100th percentile), and four public PoC/exploit references are available.

What to do: Upgrade affected WNR2000v5 routers to the latest NETGEAR-supplied firmware per the vendor's instructions (the CISA KEV required action); unpatched or end-of-life units should be replaced. As an interim mitigation, disable or restrict WAN-facing web/remote management so /apply.cgi?/lang_check.html is not reachable from untrusted networks, and review device logs for oversized hidden_lang_avi requests to that endpoint. Given confirmed in-the-wild exploitation, check exposed devices for signs of compromise.

Affected
netgear WNR2000v5 Router
netgear D6100 firmware
netgear D7000 firmware
netgear D7800 firmware
netgear JNR1010v2 firmware
netgear JNR3300 firmware
netgear JWNR2010v5 firmware
netgear R2000 firmware
netgear R6100 firmware
netgear R6220 firmware
netgear R7500 firmware
netgear R7500v2 firmware
Estimated exposure
large≈10,000–100,000 internet-exposed WNR2000v5 routers (order-of-magnitude estimate; hundreds of thousands of units plausibly deployed) — No install counts are given in the source data; the estimate is based on the WNR2000v5 being a mass-market consumer router sold through retail for several years and on public internet-scan databases historically showing thousands to tens…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

CISA Known Exploited Vulnerability
Affected
NETGEAR WNR2000v5 Router
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
netgear
Products
d6100 firmware, d7000 firmware, d7800 firmware, jnr1010v2 firmware, jnr3300 firmware, jwnr2010v5 firmware, r2000 firmware, r6100 firmware, r6220 firmware, r7500 firmware, r7500v2 firmware, wndr3700v4 firmware
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.