CISA Known Exploited Vulnerability

CVE-2016-1555

NETGEAR · Wireless Access Point (WAP) Devices

NETGEAR Multiple WAP Devices Command Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-77
Ransomware Unknown

CISA description

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

Required action

Apply updates per vendor instructions.