CVE-2016-10175

CRITICAL

NETGEAR WNR2000v5 Firmware < 1.0.0.34 - Unauthenticated Sensitive Information Exposure via BRS_netgear_success.html

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-10175. PoCs published by Pedro Ribeiro.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in NETGEAR WNR2000v5 routers, allowing remote code execution. It includes methods to bypass authentication, retrieve credentials, and execute arbitrary commands via a crafted payload.

Description

The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions.

Exploits (1)

exploitdb WORKING POC
by Pedro Ribeiro · rubyremotecgi
https://www.exploit-db.com/exploits/40949

This exploit targets a buffer overflow vulnerability in NETGEAR WNR2000v5 routers, allowing remote code execution. It includes methods to bypass authentication, retrieve credentials, and execute arbitrary commands via a crafted payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: NETGEAR WNR2000v5
No auth needed
Prerequisites: Network access to the target router · Knowledge of the router's MAC address for telnet mode
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://seclists.org/fulldisclosure/2016/Dec/72
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://raw.githubusercontent.com/pedrib/PoC/master/advisories/netgear-wnr2000.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95867
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40949/

Scores

CVSS v3 9.8
EPSS 0.8161
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (1)
netgear/wnr2000v5_firmware < 1.0.0.34
Published Jan 30, 2017
Tracked Since Feb 18, 2026