CVE-2016-10106: NETGEAR FVS318GV2 Firmware

Medium severity, CVSS 6.5. EPSS: 2.5% chance of exploitation in the next 30 days.

Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file.

Affected products

  • NETGEAR FVS318GV2 Firmware: up to and including 4.3-3.6
  • NETGEAR FVS318N Firmware: up to and including 4.3-3.6
  • NETGEAR FVS336GV3 Firmware: up to and including 4.3-3.6
  • NETGEAR SRX5308 Firmware: up to and including 4.3-3.6

Published 2017-01-03. Last modified 2026-06-17.