Remote Code Execution Vulnerability in NETGEAR Prosafe Wireless Controllers
CVE-2016-11022
7.2HIGH
Summary
The NETGEAR Prosafe Wireless Controllers WC9500, WC7600, and WC7520 have a vulnerability that allows remote attackers to gain root privileges. This is achieved through exploiting shell metacharacters in the reqMethod parameter of the login_handler.php file, potentially allowing unauthorized access and control over the affected devices. Users of these products should promptly apply security updates to mitigate the risk posed by this vulnerability.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved