CVE-2017-5900: Netcomm NB16WV-02 Firmware

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web script or HTML via the S801F0334 parameter to hdd.htm.

Affected products

  • Netcomm NB16WV-02 Firmware: version nb16wv_r0.09 only

Published 2017-03-29. Last modified 2026-06-17.