Vulnerability record · CVE-2016-10175 · published 30 January 2017
CVE-2016-10175: NETGEAR WNR2000v5 router leaks serial number via web URI
Netgear · Wnr2000v5 Firmware
The NETGEAR WNR2000v5 router exposes its serial number to unauthenticated requests for the /BRS_netgear_success.html URI. That serial number can then be combined with CVE-2016-10176, which allows resetting password-recovery answers, to derive the administrator username and password. The result is full administrative compromise of the device.
Description
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit references, and a chain to full administrative takeover justify critical priority.
What it is
The NETGEAR WNR2000v5 router exposes its serial number to unauthenticated requests for the /BRS_netgear_success.html URI. That serial number can then be combined with CVE-2016-10176, which allows resetting password-recovery answers, to derive the administrator username and password. The result is full administrative compromise of the device.
Impact
An attacker obtains the router's serial number and, chained with CVE-2016-10176, recovers the administrator username and password, gaining full control of the device.
Attack surface
Reachable over the network via an HTTP request to /BRS_netgear_success.html; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.64983 (99.2nd percentile) and public references are tagged Exploit, including a full-disclosure post and an Exploit-DB entry, indicating public exploit material exists.
What to do
- Apply the NETGEAR vendor patch referenced in advisory KB000036549.
- If the device cannot be patched, restrict access to the router's web management interface to trusted networks only.
- Disable remote/WAN administration of the router.
- Replace end-of-life WNR2000v5 units that no longer receive firmware updates.
- Change the administrator credentials and password-recovery answers after patching.
Detection
- Monitor HTTP requests to /BRS_netgear_success.html from untrusted sources.
- Alert on access to the router's web management interface from WAN or unexpected internal hosts.
- Correlate serial-number disclosure requests with subsequent password-recovery reset activity on the same device.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability | PatchVendor Advisory |
| http://seclists.org/fulldisclosure/2016/Dec/72 | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/95867 | Third Party AdvisoryVDB Entry |
| https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt | ExploitTechnical DescriptionThird Party Advisory |
| https://www.exploit-db.com/exploits/40949/ | |
| http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability | PatchVendor Advisory |
| http://seclists.org/fulldisclosure/2016/Dec/72 | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/95867 | Third Party AdvisoryVDB Entry |
| https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt | ExploitTechnical DescriptionThird Party Advisory |
| https://www.exploit-db.com/exploits/40949/ |
Track CVE-2016-10175 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-10175), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.