Apply updates per vendor instructions.
Evidence dossier
CVE-2016-1555
CVE-2016-1555
gen-409cbd0cNormalized restatement
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
- State
- PUBLISHED
- Published
- Apr 21, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 99.9%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
NETGEAR Multiple WAP Devices Command Injection Vulnerability
Probability 0.983250000000; percentile 0.999110000000
Applicability
Cited product scope
Grouped from 14 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.
Identity source boundaries
- cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
15 scope groups
[{"status": "affected", "version": "n/a"}]Version not applicableCanonical identity product-1780981622bd1910eafa81b5f138916c4eed4565ac6283ba7f377dcae31aeedblinked exactInspect 1 returned assertions
cpe:2.3:h:netgear:wn604:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd31dcaa-baa5-4463-9ea4-a7076a625407
Any version (unconstrained) (<= 3.3.2)Canonical identity product-01541bdf1b65a5aeb7e346c9bf046a11003e05d1dfff5b7e80ef32cf47563240linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:wn604_firmware:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 3.3.2
- Match ID
8ca9cfc3-d7d5-4538-aa31-9c4504e5afa7
Version not applicableCanonical identity product-f5bcf6c06c74d269301c5e9444388a9204dad7be0928d97e2ec8fb705e9cbc98linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:wn802tv2:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
05b05670-cc01-4f53-b1a7-83fe3afba12e
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-200172c4db86f8fbee4d4bd4d61f46969f0a67ead19a6c09225ce6065439105alinked exactInspect 1 returned assertions
cpe:2.3:o:netgear:wn802tv2_firmware:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 3.0.5.0
- Match ID
169f7661-bb39-4188-a26e-9791fce1da6b
Version not applicableCanonical identity product-04d90a6360cc087f00636b4e2fac753e960b117cd9c3d06c7494461994ea9722linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:wnap320:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5e2613e9-caf9-4c04-85bc-e10bdf4b0e74
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-ec07f18a8dea4c0866a9c1bb6a7fa226ef82d549b462222479af1ee84441a4a6linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:wnap320_firmware:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 3.0.5.0
- Match ID
cbce4d2f-5a11-4043-8f3e-4c10d155a6ed
Version not applicableCanonical identity product-273da0bd6682257ba5b4c0e0f928b549c8b11c1eb9538f9daf75089ac1d82862linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:wndap210v2:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5d1ad5a1-5212-4c0a-88bb-f34314f9c037
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-87092b67260f991392701d7fa7e02d4864b4f1ddc6d872fd1d67c18532860635linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:wndap210v2_firmware:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 3.0.5.0
- Match ID
9801e95c-9464-4594-b4e8-6f227c597c27
Version not applicableCanonical identity product-d539a65f1861f15a9b8cf2ebc2ce1650fd84b4f47129b89598ae5b10512eaf46linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:wndap350:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c82a16c2-dc48-4792-a4c7-8ac43f84196d
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-79d835119e429b503ca1b3bd7559c83b0a44839a407a8c64b6a76e69bac7cfb9linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:wndap350_firmware:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 3.0.5.0
- Match ID
cb422d25-d72d-445b-869d-4a5fbf285357
Version not applicableCanonical identity product-a57901335748a0666b8084d869d9dd8b1c3ce70644f8e336dfd7c4b0067ed736linked exactInspect 1 returned assertions
cpe:2.3:h:netgear:wndap360:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7975d6ec-1816-4d52-8c87-77c1b6404120
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-756749d336f7d5e4da0946cda8148f0c5635485b69e0ea2a7931d45cdb7933dflinked exactInspect 1 returned assertions
cpe:2.3:o:netgear:wndap360_firmware:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 3.0.5.0
- Match ID
fa1e8f1e-ab78-4c4b-be0b-ae17e4636077
Version not applicableCanonical identity product-8d4b687fc5968567f112b64bd7534a2ec8e1ef957f9c2d4a24dd31d85cbd55ddlinked exactInspect 1 returned assertions
cpe:2.3:h:netgear:wndap660:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
58d2492e-0cdc-4242-9206-7f0453b11cbd
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-925e19a92ab6d361ca52b79c01c96e7fff7868a1cebb9a842d3bb78110169ca7linked exactInspect 1 returned assertions
cpe:2.3:o:netgear:wndap660_firmware:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 3.0.5.0
- Match ID
99e67c3d-8907-4a96-bbaa-128959db3962
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.