← Vulnerability feed

Vulnerability record · CVE-2016-10174 · published 30 January 2017

CVE-2016-10174: NETGEAR router buffer overflow in hidden_lang_avi parameter

Netgear · D6100 Firmware

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. An unauthenticated remote attacker can exploit this overflow to achieve remote code execution on the device. The flaw is critical because it requires no credentials or user interaction and can lead to full compromise of the router.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 83% · top 0.3% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 10.0
83%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
28Affected product versions listed by NVD
13References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe vulnerability is remotely exploitable without authentication, has a CVSS score of 9.8, is listed in CISA KEV, and has a very high EPSS probability, indicating active exploitation.

What it is

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. An unauthenticated remote attacker can exploit this overflow to achieve remote code execution on the device. The flaw is critical because it requires no credentials or user interaction and can lead to full compromise of the router.

Impact

An attacker gains remote code execution on the affected router, allowing full control of the device, including manipulation of network traffic and persistence. This can lead to further compromise of the internal network.

Attack surface

The vulnerability is reachable over the network via HTTP requests to /apply.cgi?/lang_check.html, specifically through the hidden_lang_avi parameter. No authentication or user interaction is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

The vulnerability is listed in CISA KEV (added 2022-03-25) and has a high EPSS probability (0.8345, 99.665th percentile). Multiple public exploits are referenced, including Exploit-DB entries and a full disclosure advisory, indicating active exploitation in the wild.

What to do

  • Apply the vendor patch or firmware update as instructed by NETGEAR (refer to vendor advisory).
  • If patching is not immediately possible, disable remote management and restrict access to the router's web interface to trusted internal networks only.
  • Replace end-of-life devices that no longer receive firmware updates.
  • Monitor for and block exploit attempts targeting /apply.cgi?/lang_check.html at the network perimeter.

Detection

  • Inspect HTTP requests for the string 'hidden_lang_avi' or the path '/apply.cgi?/lang_check.html' in web server or IDS/IPS logs.
  • Monitor for unusual outbound connections or command execution attempts originating from router devices.
  • Use network segmentation and monitor for anomalous traffic from router management interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-10174 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-10174 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-45658Netgear d7800 firmware injection vulnerabilityCertain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6…EPSS 0.82%9.8CVE-2021-45608Netgear d7800 firmware integer overflow vulnerabilityCertain D-Link, Edimax, NETGEAR, TP-Link, Tenda, and Western Digital devices are affected by an integer overflow by an unauthenticated attacker. Remo…EPSS 2.5%9.8CVE-2021-45618Netgear d7800 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.64, EX6200v2 before 1.0.1.8…EPSS 2.0%9.8CVE-2021-45511Netgear ac2100 firmware vulnerabilityCertain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08…EPSS 18%9.8CVE-2021-45512Netgear d7000 firmware broken cryptographic algorithm vulnerabilityCertain NETGEAR devices are affected by weak cryptography. This affects D7000v2 before 1.0.0.62, D8500 before 1.0.3.50, EX3700 before 1.0.0.84, EX380…EPSS 0.54%9.8CVE-2021-45495Netgear d7000 firmware vulnerabilityNETGEAR D7000 devices before 1.0.1.68 are affected by authentication bypass.EPSS 1.6%9.8CVE-2021-45496Netgear d7000 firmware vulnerabilityNETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.EPSS 1.7%9.8CVE-2021-45497Netgear d7000 firmware vulnerabilityNETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2016-10174), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.