漏洞描述
NETGEAR WNAP320 Access Point Firmware version 2.0.3 could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/nobodyatall648/Netgear-WNAP320-Firmware-Version-2.0.3-RCE↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2016-1555↗kb.netgear.comhttps://kb.netgear.com/30480/CVE-2016-1555-Notification?cid=wmt_netgear_organic↗seclists.orghttp://seclists.org/fulldisclosure/2016/Feb/112↗packetstormsecurity.comhttp://packetstormsecurity.com/files/135956/D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html↗