CVE-2016-5649 describes an authentication bypass vulnerability in the Netgear DGN2200 (firmware DGN2200-V1.0.0.50_7.0.50) and DGND3700 (firmware DGND3700-V1.0.0.17_1.0.17) routers. A remote attacker can access the 'BSW_cxttongr.htm' page without authentication, which then exposes the administrator password in clear text. This critical vulnerability (CVSS 9.8) allows for complete compromise of the router's web interface, as an attacker can gain full administrative access. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for detecting this flaw, and its EPSS score indicates a higher than average exploitability probability. Despite its severity, there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.50_7.0.50CPE matchmatch criteria | cpe:2.3:o:netgear:dgn2200_firmware:1.0.0.50_7.0.50:*:*:*:*:*:*:* | ||
1.0.0.17_1.0.17CPE matchmatch criteria | cpe:2.3:o:netgear:dgnd3700_firmware:1.0.0.17_1.0.17:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.