CVE-2016-1555
KEV PoC largeUnauthenticated Command Injection RCE in NETGEAR Business Wireless Access Points
CISA: NETGEAR Multiple WAP Devices Command Injection Vulnerability
CVE-2016-1555 is a critical (CVSS 9.8) unauthenticated command injection flaw (CWE-77) in the boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php, and boardDataWW.php management pages of seven NETGEAR wireless access point models. An attacker who can reach these web endpoints over the network can pass crafted input to the scripts and execute arbitrary operating-system commands on the access point, with no login, privilege, or user interaction required. Successful exploitation grants full control of the device, letting attackers use it as a foothold or conscript it into IoT botnets such as BotenaGo, which reportedly uses 33 exploits to target millions of IoT devices. Only the NETGEAR WN604 (firmware before 3.3.3) and the WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 (firmware before 3.5.5.0) are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), has a public proof-of-concept on Exploit-DB, and carries an EPSS score of 98.3%, so defenders should treat it as actively exploited in the wild.
What to do: Upgrade the WN604 to firmware 3.3.3 or later and the WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 to firmware 3.5.5.0 or later, per NETGEAR's instructions. Until patched, do not expose these access points' web management interface to the internet and restrict administration to a trusted management VLAN or VPN; if current firmware is no longer obtainable for a given model, consider isolating or replacing the device. Review device and web-server logs for suspicious requests to the boardData*.php endpoints as a sign of attempted or successful exploitation.
| NETGEAR WN604 wireless access point | firmware before 3.3.3 |
| NETGEAR WN802Tv2 wireless access point | firmware before 3.5.5.0 |
| NETGEAR WNAP210v2 wireless access point | firmware before 3.5.5.0 |
| NETGEAR WNAP320 wireless access point | firmware before 3.5.5.0 |
| NETGEAR WNDAP350 wireless access point | firmware before 3.5.5.0 |
| NETGEAR WNDAP360 wireless access point | firmware before 3.5.5.0 |
| NETGEAR WNDAP660 wireless access point | firmware before 3.5.5.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
- Affected
- NETGEAR Wireless Access Point (WAP) Devices
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- netgear
- Products
- wnap320 firmware, wndap350 firmware, wndap360 firmware, wndap210v2 firmware, wn604 firmware, wndap660 firmware, wn802tv2 firmware
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H