← Vulnerability feed

Vulnerability record · CVE-2016-11055 · published 28 April 2020

CVE-2016-11055: Netgear cm400 firmware cross-site request forgery vulnerability

Netgear · Cm400 Firmware

Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 before 2017-01-11, JWNR2000Tv3 before 2017-01-11, JWNR2010v3 before 2017-01-11, PLW1000 before 2017-01-11, PLW1010 before 2017-01-11, WNR500 before 2017-01-11, WNR612v3 before 2017-01-11, N450 before 2017-01-11, and CG3000Dv2 before 2017-01-11.

4.3 CVSS 3.1 Medium EPSS 0.35% · top 73.7% CWE-352 · Cross-site request forgery
4.3CVSS 3.1 base score, v2 4.3
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 before 2017-01-11, JWNR2000Tv3 before 2017-01-11, JWNR2010v3 before 2017-01-11, PLW1000 before 2017-01-11, PLW1010 before 2017-01-11, WNR500 before 2017-01-11, WNR612v3 before 2017-01-11, N450 before 2017-01-11, and CG3000Dv2 before 2017-01-11.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-11055 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-18703Netgear d1500 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50,…EPSS 0.46%7.5CVE-2016-11059Netgear ac1450 firmware information exposure vulnerabilityCertain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before 2017-01-06, D500 before 2017-01-06, D1…EPSS 1.1%7.5CVE-2017-18859Netgear c6300 firmware vulnerabilityCertain NETGEAR devices are affected by slowdown/stoppage. This affects C6300 before 2017-05-30, CM400 before 2017-05-30, CM700 before 2017-05-30, an…EPSS 1.0%7.5CVE-2018-21139Netgear d1500 firmware information exposure vulnerabilityCertain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1…EPSS 1.2%6.5CVE-2017-18766Netgear dst6501 firmware information exposure vulnerabilityCertain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects DST6501 before 1.1.0.6 and WNR2000v2 before 1.2.0…EPSS 0.53%6.2CVE-2017-18798Netgear r6700 firmware improper input validation vulnerabilityCertain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, D7…EPSS 0.37%5.4CVE-2018-21231Netgear d1500 firmware vulnerabilityCertain NETGEAR devices are affected by incorrect configuration of security settings. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100…EPSS 0.47%5.4CVE-2018-21230Netgear d1500 firmware vulnerabilityCertain NETGEAR devices are affected by incorrect configuration of security settings. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100…EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2016-11055), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.