Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2016-1555

Description

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

POC

Reference

- http://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html

- https://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic

- https://www.exploit-db.com/exploits/45909/

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/ARPSyndicate/cvemon

- https://github.com/ARPSyndicate/kenzer-templates

- https://github.com/Ivan0719/Workshop212

- https://github.com/MercuryNearTheMoon/NetGear-WNAP320-CVEs

- https://github.com/Ostorlab/KEV

- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors

- https://github.com/faisalfs10x/faisalfs10x

- https://github.com/ide0x90/cve-2016-1555

- https://github.com/ker2x/DearDiary

- https://github.com/north-vuln-intel/nuclei-nvi

- https://github.com/padresvater/Mobile-Internet-Security

- https://github.com/zyw-200/EQUAFL_setup