Vulnerability record · CVE-2016-10174 · published 30 January 2017
CVE-2016-10174: NETGEAR router buffer overflow in hidden_lang_avi parameter
Netgear · D6100 Firmware
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. An unauthenticated remote attacker can exploit this overflow to achieve remote code execution on the device. The flaw is critical because it requires no credentials or user interaction and can lead to full compromise of the router.
Description
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is remotely exploitable without authentication, has a CVSS score of 9.8, is listed in CISA KEV, and has a very high EPSS probability, indicating active exploitation.
What it is
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. An unauthenticated remote attacker can exploit this overflow to achieve remote code execution on the device. The flaw is critical because it requires no credentials or user interaction and can lead to full compromise of the router.
Impact
An attacker gains remote code execution on the affected router, allowing full control of the device, including manipulation of network traffic and persistence. This can lead to further compromise of the internal network.
Attack surface
The vulnerability is reachable over the network via HTTP requests to /apply.cgi?/lang_check.html, specifically through the hidden_lang_avi parameter. No authentication or user interaction is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
The vulnerability is listed in CISA KEV (added 2022-03-25) and has a high EPSS probability (0.8345, 99.665th percentile). Multiple public exploits are referenced, including Exploit-DB entries and a full disclosure advisory, indicating active exploitation in the wild.
What to do
- Apply the vendor patch or firmware update as instructed by NETGEAR (refer to vendor advisory).
- If patching is not immediately possible, disable remote management and restrict access to the router's web interface to trusted internal networks only.
- Replace end-of-life devices that no longer receive firmware updates.
- Monitor for and block exploit attempts targeting /apply.cgi?/lang_check.html at the network perimeter.
Detection
- Inspect HTTP requests for the string 'hidden_lang_avi' or the path '/apply.cgi?/lang_check.html' in web server or IDS/IPS logs.
- Monitor for unusual outbound connections or command execution attempts originating from router devices.
- Use network segmentation and monitor for anomalous traffic from router management interfaces.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-10174 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-10174 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-10174), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.