CVE-2016-10115: NETGEAR Arlo Base Station Firmware

Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.

NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory configuration.

Affected products

  • NETGEAR Arlo Base Station Firmware: up to and including 1.7.5_6178
  • NETGEAR Arlo Q Camera Firmware: up to and including 1.8.0_5551
  • NETGEAR Arlo Q Plus Camera Firmware: up to and including 1.8.1_6094

Published 2017-01-04. Last modified 2026-06-17.