Vulnerability record · CVE-2016-1555 · published 21 April 2017
CVE-2016-1555: Netgear wireless access point PHP scripts allow unauthenticated command injection
Netgear · Wnap320 Firmware
Several PHP scripts (boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php, boardDataWW.php) in Netgear WN604 and multiple WNAP/WNDAP access points pass attacker input to a command shell without sanitisation. A remote, unauthenticated attacker can run arbitrary commands on the device. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with a CVSS score of 9.8, confirmed exploitation in KEV and public exploit code.
What it is
Several PHP scripts (boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php, boardDataWW.php) in Netgear WN604 and multiple WNAP/WNDAP access points pass attacker input to a command shell without sanitisation. A remote, unauthenticated attacker can run arbitrary commands on the device. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker gains arbitrary command execution with the privileges of the web server, allowing full compromise of the access point and any network it bridges.
Attack surface
Reachable over the network through the device web interface via the affected boardData PHP scripts; the CVSS vector shows no privileges and no user interaction required.
Exploitation
CISA added it to KEV on 2022-03-25 with a 2022-04-15 remediation due date, and public exploit code exists on Exploit-DB; EPSS 30-day probability is about 0.98.
What to do
- Apply the vendor firmware updates: WN604 3.3.3 or later and WNAP/WNDAP 3.5.5.0 or later.
- If patching is not possible, remove the devices from untrusted networks and restrict management access to a dedicated VLAN.
- Disable remote management and block internet exposure of the web interface.
- Replace end-of-life models that no longer receive firmware updates.
- Monitor vendor advisories for further updates on these product lines.
Detection
- Inspect web server and system logs for requests to boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php or boardDataWW.php.
- Alert on shell metacharacters or command strings in HTTP parameters sent to those scripts.
- Watch for unexpected outbound connections or new processes on the access point.
- Review network traffic to and from access point management interfaces for anomalous requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-1555 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "NETGEAR Multiple WAP Devices Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html | Third Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2016/Feb/112 | Mailing ListThird Party Advisory |
| https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45909/ | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html | Third Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2016/Feb/112 | Mailing ListThird Party Advisory |
| https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45909/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-1555 | US Government Resource |
Track CVE-2016-1555 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-1555), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.