Evidence dossier

CVE-2016-10174

CVE-2016-10174

82.898.3Priority evidence range
As known Jul 21, 2026, 8:13 AM UTCgen-409cbd0c

Normalized restatement

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

State
PUBLISHED
Published
Jan 30, 2017
Updated
Oct 21, 2025
Evidence coverage
72%
CISA KEVCatalog member

Apply updates per vendor instructions.

FIRST EPSS83.45%

2026-07-18 · v2026.06.15 · percentile 99.7%

Source stateConflict visible

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

mitreoriginal assertion
container

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

CISA KEVoriginal assertion
observed_exploitation

NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.834500000000; percentile 0.996520000000

Applicability

Cited product scope

Trace impact →
56Underlying assertions
56Canonical products
28Target assertions
28Constraint assertions

Grouped from 56 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.

Identity source boundaries
  • cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

57 scope groups

mitre · source assertedn/an/aDirect source scope
[{"status": "affected", "version": "n/a"}]
unknown
NVD CPE · HARDWAREnetgeard6100Environmental constraint · 1 assertions
Version not applicableCanonical identity product-e819d986713af85c12186e708945b604f007530945d57bc7486d63c208add256linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:d6100:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7efd1e86-f100-4e46-935d-903eb6fefe9d
NVD CPE · OPERATING SYSTEMnetgeard6100_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-de68a5bb6076ac6bdaa566d12885befeca18179d6e2b05609f2208fea393b381linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:d6100_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5b7c04a4-4b5c-42d8-a6c7-8dafcc53c0ba
NVD CPE · HARDWAREnetgeard7000Environmental constraint · 1 assertions
Version not applicableCanonical identity product-4625af6b646bd3dc9d703ad49fcf4c56899d9ff99675612f88edbe31b11cb606linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:d7000:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    af04b65b-9685-4595-9c71-0f77ad7109be
NVD CPE · OPERATING SYSTEMnetgeard7000_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-ef33086914238e014b84ca85efe2484da2cd04f829069057d1b2e6681629712flinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:d7000_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    826e2415-7eb3-4f34-8c9d-87a89bb9d6d6
NVD CPE · HARDWAREnetgeard7800Environmental constraint · 1 assertions
Version not applicableCanonical identity product-ae002f05030935001e45acfa1367235e8f0be7c663e7c5ee0c52ff069de56761linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:d7800:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    da2d4987-3726-4a72-8d32-592f59fac46d
NVD CPE · OPERATING SYSTEMnetgeard7800_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-36d5efe81ee1ba742919808cfa883f9ee0f0d2319c34dfdc9f0e22f6e7e366aclinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:d7800_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    92c0a12d-9eee-4dfc-8985-53d06240bbb6
NVD CPE · HARDWAREnetgearjnr1010v2Environmental constraint · 1 assertions
Version not applicableCanonical identity product-df1315d322a32a246f41dbcb7209cd38f080d91d483b0b6347b285c7961928b3linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:jnr1010v2:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    91a302bb-1250-439a-947a-5727db1ce88e
NVD CPE · OPERATING SYSTEMnetgearjnr1010v2_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-631a52e95d2798441c2b37fd19de582fdfef2eea3e93e22019e2f7f78105d953linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:jnr1010v2_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b7617f12-efcc-4771-ac36-cb91e36dc7c6
NVD CPE · HARDWAREnetgearjnr3300Environmental constraint · 1 assertions
Version not applicableCanonical identity product-1b635486281053a92f6500eb2647cdd89deb4bfef5e4f9c551d908935909bc61linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:jnr3300:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    64ca12cc-48d8-4510-983c-8350a87cd5d2
NVD CPE · OPERATING SYSTEMnetgearjnr3300_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-d61e4a45c216ef7c59cd7cfc86492a18fa67c24e3eae217715fae5bff77cb388linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:jnr3300_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5865c3f2-1be0-476b-a70f-a0cb01cd71eb
NVD CPE · HARDWAREnetgearjwnr2010v5Environmental constraint · 1 assertions
Version not applicableCanonical identity product-c02e12be2f063be046cde59791b8e144de48446b800fe58341834498713a962blinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:jwnr2010v5:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3674693f-8324-4279-a402-556d5c6f31b8
NVD CPE · OPERATING SYSTEMnetgearjwnr2010v5_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-b1001cccd41cbdb893c457855c5e813dafa21277d7b86455a1d5a1a0c159a20clinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:jwnr2010v5_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    66148f9b-3495-4a62-83e7-14add4ac1f37
NVD CPE · HARDWAREnetgearr2000Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d02666022ec26b89e3c73c78be9dd428a493e95d9b38910cc6f409d81cf65b4alinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:r2000:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9b1d13c3-5663-447f-9fd9-71ebec471daf
NVD CPE · OPERATING SYSTEMnetgearr2000_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-25620fc3bd791bf9bee4582615a3cb08eef08a2ad5fea38381a34339aa19b740linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:r2000_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e70db74e-a2e6-4f71-a066-282dc90db603
NVD CPE · HARDWAREnetgearr6100Environmental constraint · 1 assertions
Version not applicableCanonical identity product-112207fd19763bc7661233c6a49b8196dd398284784a4c3a84813b177ff67a57linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:r6100:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f44a123-b256-428b-98c2-17570f2f32dc
NVD CPE · OPERATING SYSTEMnetgearr6100_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-73e259909c7501d30f65f436e3207f9db86131312c0a7f1ae90f8ed8b120083flinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:r6100_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cc498419-5d49-45d7-a941-3f7fbd4ca79d
NVD CPE · HARDWAREnetgearr6220Environmental constraint · 1 assertions
Version not applicableCanonical identity product-1c5c55e51f7871ce5d16eb274511cf67e602421f32dfc79da901fb000d10ca15linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:r6220:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b131b5c8-cb7f-433b-ba32-f05ce0e92a66
NVD CPE · OPERATING SYSTEMnetgearr6220_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-0fb158c1e51c9efab5ec742cd25cbfd78a659a7fb82a02f6665489c9bcb28451linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:r6220_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2513fc0e-56a6-4e13-9f08-015b3dd22229
NVD CPE · HARDWAREnetgearr7500Environmental constraint · 1 assertions
Version not applicableCanonical identity product-a69dc7fa877966fe6cb6273d89af3d659cfcde08153df287c6da7f807ca4621blinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:r7500:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ef3b3f26-401c-4ed0-b871-4b4f8521f369
NVD CPE · OPERATING SYSTEMnetgearr7500_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-9333bad6a859159321240bf6078c59c7d7a1db0a6dc74c70c4e7505325ca9ac0linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:r7500_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    17340c25-0b87-4ae3-b11e-b5b2367823a3
NVD CPE · HARDWAREnetgearr7500v2Environmental constraint · 1 assertions
Version not applicableCanonical identity product-34972aaedfdce79b62d2a7ff06ebe2b7e81817567502ba71f105c06457734b1flinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:r7500v2:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2bca6487-57ec-4630-884f-820bbfe25843
NVD CPE · OPERATING SYSTEMnetgearr7500v2_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-b066334fd650ef5313eba78a9d138509d9e39e5344f6ef9f76ca97ab0586ed5blinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:r7500v2_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    86eb56e2-afe5-4b5a-8b08-ff76188217d7
NVD CPE · HARDWAREnetgearwndr3700v4Environmental constraint · 1 assertions
Version not applicableCanonical identity product-8bcce761a265e9faa4e75794351ba77f9d2ce99f7e175851d7d89c2e89a5efe0linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:wndr3700v4:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cf63301f-c798-471e-abf7-5a7e72e8588c
NVD CPE · OPERATING SYSTEMnetgearwndr3700v4_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-29f00696e769910eafc671f7d4f2aea167058b0dd4e7e4d3c3ceed4ebd0da35blinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:wndr3700v4_firmware:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd0d1be2-6b68-4064-8def-ff56452e37b9

Assessments

CVSS by origin

9.8
nvd@nist.govCVSS 3.1 · role PrimaryCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
nvd@nist.govCVSS 2.0 · role PrimaryAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.