CVE-2016-1555 is a critical remote command execution vulnerability affecting multiple Netgear WN and WNDAP series wireless access points and routers, specifically within several boardData PHP scripts. This flaw allows unauthenticated remote attackers to execute arbitrary commands on affected devices. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, listed in CISA's KEV catalog, and has readily available exploit code, including Metasploit modules and Nuclei templates, indicating widespread community and attacker interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.5.0CPE matchmatch criteria | cpe:2.3:o:netgear:wnap320_firmware:*:*:*:*:*:*:*:* | ||
<= 3.0.5.0CPE matchmatch criteria | cpe:2.3:o:netgear:wndap350_firmware:*:*:*:*:*:*:*:* | ||
<= 3.0.5.0CPE matchmatch criteria | cpe:2.3:o:netgear:wndap360_firmware:*:*:*:*:*:*:*:* | ||
<= 3.0.5.0CPE matchmatch criteria | cpe:2.3:o:netgear:wndap210v2_firmware:*:*:*:*:*:*:*:* | ||
<= 3.3.2CPE matchmatch criteria | cpe:2.3:o:netgear:wn604_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.