CVE-2016-11022: NETGEAR Prosafe WC7520 Firmware
High severity, CVSS 7.2. EPSS: 3.2% chance of exploitation in the next 30 days.
NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php.
Affected products
- NETGEAR Prosafe WC7520 Firmware: version 2.5.0.35 only
- NETGEAR Prosafe WC7600 Firmware: version 5.1.0.17 only
- NETGEAR Prosafe WC9500 Firmware: version 5.1.0.17 only
Published 2020-03-23. Last modified 2026-06-17.