Vulnerability record · CVE-2016-10176 · published 30 January 2017
CVE-2016-10176: NETGEAR WNR2000v5 router unauthenticated command execution via apply_noauth.cgi
Netgear · Wnr2000v5 Firmware
The NETGEAR WNR2000v5 web server (uhttpd) exposes an apply_noauth.cgi endpoint that lets an unauthenticated user perform sensitive actions normally reserved for an authenticated administrator. This allows an attacker to change router settings, including password-recovery answers, and ultimately achieve remote code execution. The flaw is remotely reachable with no credentials or user interaction, making it a critical exposure for any internet-facing device.
Description
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and processed accordingly. The web server also contains another URL, apply_noauth.cgi, that allows an unauthenticated user to perform sensitive actions on the device. This functionality can be exploited to change the router settings (such as the answers to the password-recovery questions) and achieve remote code execution.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a critical CVSS score, public exploit references, and a very high EPSS probability.
What it is
The NETGEAR WNR2000v5 web server (uhttpd) exposes an apply_noauth.cgi endpoint that lets an unauthenticated user perform sensitive actions normally reserved for an authenticated administrator. This allows an attacker to change router settings, including password-recovery answers, and ultimately achieve remote code execution. The flaw is remotely reachable with no credentials or user interaction, making it a critical exposure for any internet-facing device.
Impact
An attacker gains full control of the router's configuration and can execute arbitrary code on the device. That enables traffic interception, redirection, persistence, and use of the router as a foothold into the internal network.
Attack surface
Reachable over the network through the device's embedded web server on the apply_noauth.cgi URL. No authentication and no user interaction are required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.77577, 99.5th percentile) and multiple references are tagged Exploit, including public advisories and an Exploit-DB entry, indicating public exploit code exists.
What to do
- Apply the vendor patch referenced in NETGEAR advisory 000036549 as the first action.
- If the device cannot be patched, remove it from internet exposure and restrict management access to a trusted internal network only.
- Disable or block access to apply_noauth.cgi and apply.cgi at any upstream proxy or firewall where possible.
- Replace end-of-life WNR2000v5 units that no longer receive firmware updates.
- Change default administrative credentials and password-recovery answers after remediation.
Detection
- Monitor web server logs for requests to apply_noauth.cgi or apply.cgi from untrusted or external sources.
- Alert on configuration changes to router settings, especially password-recovery questions, outside maintenance windows.
- Watch for unexpected outbound connections or DNS changes originating from the router.
- Use network monitoring to detect scanning or exploitation attempts against the router's management interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability | PatchVendor Advisory |
| http://seclists.org/fulldisclosure/2016/Dec/72 | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/95867 | Third Party AdvisoryVDB Entry |
| https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt | ExploitTechnical DescriptionThird Party Advisory |
| https://www.exploit-db.com/exploits/40949/ | |
| http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability | PatchVendor Advisory |
| http://seclists.org/fulldisclosure/2016/Dec/72 | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/95867 | Third Party AdvisoryVDB Entry |
| https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt | ExploitTechnical DescriptionThird Party Advisory |
| https://www.exploit-db.com/exploits/40949/ |
Track CVE-2016-10176 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-10176), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.