← Vulnerability feed

Vulnerability record · CVE-2016-1555 · published 21 April 2017

CVE-2016-1555: Netgear wireless access point PHP scripts allow unauthenticated command injection

Netgear · Wnap320 Firmware

Several PHP scripts (boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php, boardDataWW.php) in Netgear WN604 and multiple WNAP/WNDAP access points pass attacker input to a command shell without sanitisation. A remote, unauthenticated attacker can run arbitrary commands on the device. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 98% · top 0.1% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 10.0
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a CVSS score of 9.8, confirmed exploitation in KEV and public exploit code.

What it is

Several PHP scripts (boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php, boardDataWW.php) in Netgear WN604 and multiple WNAP/WNDAP access points pass attacker input to a command shell without sanitisation. A remote, unauthenticated attacker can run arbitrary commands on the device. The flaw is rated critical and is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker gains arbitrary command execution with the privileges of the web server, allowing full compromise of the access point and any network it bridges.

Attack surface

Reachable over the network through the device web interface via the affected boardData PHP scripts; the CVSS vector shows no privileges and no user interaction required.

Exploitation

CISA added it to KEV on 2022-03-25 with a 2022-04-15 remediation due date, and public exploit code exists on Exploit-DB; EPSS 30-day probability is about 0.98.

What to do

  • Apply the vendor firmware updates: WN604 3.3.3 or later and WNAP/WNDAP 3.5.5.0 or later.
  • If patching is not possible, remove the devices from untrusted networks and restrict management access to a dedicated VLAN.
  • Disable remote management and block internet exposure of the web interface.
  • Replace end-of-life models that no longer receive firmware updates.
  • Monitor vendor advisories for further updates on these product lines.

Detection

  • Inspect web server and system logs for requests to boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php or boardDataWW.php.
  • Alert on shell metacharacters or command strings in HTTP parameters sent to those scripts.
  • Watch for unexpected outbound connections or new processes on the access point.
  • Review network traffic to and from access point management interfaces for anomalous requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-1555 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "NETGEAR Multiple WAP Devices Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-1555 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-21097Netgear wac505 firmware out-of-bounds write vulnerabilityCertain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects WAC505 before 5.0.5.4, WAC510 befo…EPSS 1.2%9.8CVE-2016-1557Netgear wnap320 firmware information exposure vulnerabilityNetgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwords over SNMP.EPSS 2.8%8.0CVE-2018-21120Netgear wac120 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4…EPSS 0.46%7.5CVE-2016-1556Netgear wnap320 firmware information exposure vulnerabilityInformation disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote…EPSS 3.5%7.4CVE-2018-21096Netgear wac120 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4…EPSS 0.31%7.3CVE-2018-21094Netgear wac120 firmware vulnerabilityCertain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510…EPSS 1.0%7.1CVE-2017-18863Netgear wn604 firmware injection vulnerabilityCertain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v2 3.5.20.0 and earlier, WNAP3…EPSS 0.50%6.7CVE-2017-18805Netgear wac510 firmware injection vulnerabilityCertain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 be…EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2016-1555), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.