LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-10174: NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-10174 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

CVE-2016-10174 is a buffer overflow vulnerability in the NETGEAR WNR2000v5 router that can be exploited to achieve remote code execution. For IT and security teams, this matters because a compromised consumer or small-office router can give an attacker a foothold on the network edge, enabling further lateral movement, traffic interception, or persistent access until the device is remediated.

Public detail is limited to the product and weakness class described in the advisory material. Confirm exact impact, fixed firmware, and any prerequisites against the vendor advisory before acting.

How it works

This issue is classed as CWE-119: improper restriction of operations within the bounds of a memory buffer. In products of this type, a buffer overflow typically occurs when input is copied or processed without adequate length checks, allowing data to overwrite adjacent memory.

An attacker who can reach the vulnerable service or interface on the router may send crafted input that triggers the overflow. Successful exploitation can lead to remote code execution on the device, giving the attacker control at the privilege level of the affected process. Specific exploit mechanics, required access path (for example LAN versus WAN), and preconditions are not detailed in the provided facts and must be confirmed against the vendor advisory. Do not assume unauthenticated internet-wide reachability without that confirmation.

Am I affected? How to find it in your systems

The affected product is the NETGEAR WNR2000v5 router. These devices commonly appear in home, branch, or small-office networks as the primary gateway, and sometimes in lab or secondary networks where older consumer hardware remains in use.

How to remediate

Patch first. Apply updates per vendor instructions, as required by the CISA guidance associated with this CVE. Obtain the fixed firmware only from NETGEAR’s official support channels, verify integrity if the vendor provides checksums or signatures, and follow the documented upgrade procedure for the WNR2000v5.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to edge routers and buffer-overflow risks.

These steps lower likelihood and impact; they do not replace the vendor fix. Schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited remote-code-execution flaws on network devices can lead to full device compromise and subsequent breaches of traffic or credentials that traverse the router. Known ransomware use is not documented for this CVE in the provided facts. If you suspect exploitation, isolate the device, preserve logs and firmware images for analysis, rotate credentials that may have been handled by the router, and follow your incident-response process. You can run a free exposure scan of your email addresses with a reputable breach-notification service to check whether associated accounts appear in known breach datasets and then prioritize password and MFA hygiene accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNETGEAR · WNR2000v5 Router
WeaknessCWE-119
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities