Apply updates per vendor instructions.
Evidence dossier
CVE-2016-10174
CVE-2016-10174
gen-409cbd0cNormalized restatement
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
- State
- PUBLISHED
- Published
- Jan 30, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 99.7%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability
Probability 0.834500000000; percentile 0.996520000000
Applicability
Cited product scope
Grouped from 56 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.
Identity source boundaries
- cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
57 scope groups
[{"status": "affected", "version": "n/a"}]Version not applicableCanonical identity product-e819d986713af85c12186e708945b604f007530945d57bc7486d63c208add256linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:d6100:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7efd1e86-f100-4e46-935d-903eb6fefe9d
Version not applicableCanonical identity product-de68a5bb6076ac6bdaa566d12885befeca18179d6e2b05609f2208fea393b381linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:d6100_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5b7c04a4-4b5c-42d8-a6c7-8dafcc53c0ba
Version not applicableCanonical identity product-4625af6b646bd3dc9d703ad49fcf4c56899d9ff99675612f88edbe31b11cb606linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:d7000:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
af04b65b-9685-4595-9c71-0f77ad7109be
Version not applicableCanonical identity product-ef33086914238e014b84ca85efe2484da2cd04f829069057d1b2e6681629712flinked exactInspect 1 returned assertions
cpe:2.3:o:netgear:d7000_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
826e2415-7eb3-4f34-8c9d-87a89bb9d6d6
Version not applicableCanonical identity product-ae002f05030935001e45acfa1367235e8f0be7c663e7c5ee0c52ff069de56761linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:d7800:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
da2d4987-3726-4a72-8d32-592f59fac46d
Version not applicableCanonical identity product-36d5efe81ee1ba742919808cfa883f9ee0f0d2319c34dfdc9f0e22f6e7e366aclinked exactInspect 1 returned assertions
cpe:2.3:o:netgear:d7800_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
92c0a12d-9eee-4dfc-8985-53d06240bbb6
Version not applicableCanonical identity product-df1315d322a32a246f41dbcb7209cd38f080d91d483b0b6347b285c7961928b3linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:jnr1010v2:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
91a302bb-1250-439a-947a-5727db1ce88e
Version not applicableCanonical identity product-631a52e95d2798441c2b37fd19de582fdfef2eea3e93e22019e2f7f78105d953linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:jnr1010v2_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b7617f12-efcc-4771-ac36-cb91e36dc7c6
Version not applicableCanonical identity product-1b635486281053a92f6500eb2647cdd89deb4bfef5e4f9c551d908935909bc61linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:jnr3300:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
64ca12cc-48d8-4510-983c-8350a87cd5d2
Version not applicableCanonical identity product-d61e4a45c216ef7c59cd7cfc86492a18fa67c24e3eae217715fae5bff77cb388linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:jnr3300_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5865c3f2-1be0-476b-a70f-a0cb01cd71eb
Version not applicableCanonical identity product-c02e12be2f063be046cde59791b8e144de48446b800fe58341834498713a962blinked exactInspect 1 returned assertions
cpe:2.3:h:netgear:jwnr2010v5:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3674693f-8324-4279-a402-556d5c6f31b8
Version not applicableCanonical identity product-b1001cccd41cbdb893c457855c5e813dafa21277d7b86455a1d5a1a0c159a20clinked exactInspect 1 returned assertions
cpe:2.3:o:netgear:jwnr2010v5_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
66148f9b-3495-4a62-83e7-14add4ac1f37
Version not applicableCanonical identity product-d02666022ec26b89e3c73c78be9dd428a493e95d9b38910cc6f409d81cf65b4alinked exactInspect 1 returned assertions
cpe:2.3:h:netgear:r2000:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9b1d13c3-5663-447f-9fd9-71ebec471daf
Version not applicableCanonical identity product-25620fc3bd791bf9bee4582615a3cb08eef08a2ad5fea38381a34339aa19b740linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:r2000_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e70db74e-a2e6-4f71-a066-282dc90db603
Version not applicableCanonical identity product-112207fd19763bc7661233c6a49b8196dd398284784a4c3a84813b177ff67a57linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:r6100:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f44a123-b256-428b-98c2-17570f2f32dc
Version not applicableCanonical identity product-73e259909c7501d30f65f436e3207f9db86131312c0a7f1ae90f8ed8b120083flinked exactInspect 1 returned assertions
cpe:2.3:o:netgear:r6100_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cc498419-5d49-45d7-a941-3f7fbd4ca79d
Version not applicableCanonical identity product-1c5c55e51f7871ce5d16eb274511cf67e602421f32dfc79da901fb000d10ca15linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:r6220:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b131b5c8-cb7f-433b-ba32-f05ce0e92a66
Version not applicableCanonical identity product-0fb158c1e51c9efab5ec742cd25cbfd78a659a7fb82a02f6665489c9bcb28451linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:r6220_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2513fc0e-56a6-4e13-9f08-015b3dd22229
Version not applicableCanonical identity product-a69dc7fa877966fe6cb6273d89af3d659cfcde08153df287c6da7f807ca4621blinked exactInspect 1 returned assertions
cpe:2.3:h:netgear:r7500:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ef3b3f26-401c-4ed0-b871-4b4f8521f369
Version not applicableCanonical identity product-9333bad6a859159321240bf6078c59c7d7a1db0a6dc74c70c4e7505325ca9ac0linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:r7500_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
17340c25-0b87-4ae3-b11e-b5b2367823a3
Version not applicableCanonical identity product-34972aaedfdce79b62d2a7ff06ebe2b7e81817567502ba71f105c06457734b1flinked exactInspect 1 returned assertions
cpe:2.3:h:netgear:r7500v2:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2bca6487-57ec-4630-884f-820bbfe25843
Version not applicableCanonical identity product-b066334fd650ef5313eba78a9d138509d9e39e5344f6ef9f76ca97ab0586ed5blinked exactInspect 1 returned assertions
cpe:2.3:o:netgear:r7500v2_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
86eb56e2-afe5-4b5a-8b08-ff76188217d7
Version not applicableCanonical identity product-8bcce761a265e9faa4e75794351ba77f9d2ce99f7e175851d7d89c2e89a5efe0linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:wndr3700v4:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cf63301f-c798-471e-abf7-5a7e72e8588c
Version not applicableCanonical identity product-29f00696e769910eafc671f7d4f2aea167058b0dd4e7e4d3c3ceed4ebd0da35blinked exactInspect 1 returned assertions
cpe:2.3:o:netgear:wndr3700v4_firmware:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd0d1be2-6b68-4064-8def-ff56452e37b9
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.