Back
CVE-2016-10175
CRITICAL
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions.
Published: Jan 30, 2017
Modified: Jun 17, 2026
CWE-200
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| netgear | wnr2000v5_firmware | * |
GitHub Security Advisory GHSA-ghhf-xp94-4ggw
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the ...
References (10)
- http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability Patch, Vendor Advisory
- http://seclists.org/fulldisclosure/2016/Dec/72 Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95867 Third Party Advisory, VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt Exploit, Technical Description, Third Party Advisory
- https://www.exploit-db.com/exploits/40949/
- http://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability Patch, Vendor Advisory
- http://seclists.org/fulldisclosure/2016/Dec/72 Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95867 Third Party Advisory, VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt Exploit, Technical Description, Third Party Advisory
- https://www.exploit-db.com/exploits/40949/
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
64.98%
Top 1% most likely to be exploited
Threat Score
58.7 / 100
Data Sources
NVD
EPSS
GitHub