CVE-2016-10176 is a critical vulnerability affecting NETGEAR WNR2000v5 routers, allowing unauthenticated attackers to perform sensitive actions and achieve remote code execution by exploiting the apply_noauth.cgi URL. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this flaw enables complete compromise of the device, including changing router settings and executing arbitrary code. Exploit code is publicly available via Metasploit and ExploitDB, and the vulnerability has garnered significant community discussion and media coverage, including its use in malware campaigns like RouteX, despite not being listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.0.34CPE matchmatch criteria | cpe:2.3:o:netgear:wnr2000v5_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.