CVE-2016-1555: NETGEAR Multiple WAP Devices Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 98.3% chance of exploitation in the next 30 days.
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
Affected products
- NETGEAR WN604 Firmware: up to and including 3.3.2
- NETGEAR WN802TV2 Firmware: up to and including 3.0.5.0
- NETGEAR WNAP320 Firmware: up to and including 3.0.5.0
- NETGEAR WNDAP210V2 Firmware: up to and including 3.0.5.0
- NETGEAR WNDAP350 Firmware: up to and including 3.0.5.0
- NETGEAR WNDAP360 Firmware: up to and including 3.0.5.0
- NETGEAR WNDAP660 Firmware: up to and including 3.0.5.0
Published 2017-04-21. Last modified 2026-06-17.