Evidence dossier

CVE-2016-1555

CVE-2016-1555

84.399.8Priority evidence range
As known Jul 21, 2026, 8:13 AM UTCgen-409cbd0c

Normalized restatement

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

State
PUBLISHED
Published
Apr 21, 2017
Updated
Oct 21, 2025
Evidence coverage
72%
CISA KEVCatalog member

Apply updates per vendor instructions.

FIRST EPSS98.32%

2026-07-18 · v2026.06.15 · percentile 99.9%

Source stateConflict visible

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

certccoriginal assertion
container

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

CISA KEVoriginal assertion
observed_exploitation

NETGEAR Multiple WAP Devices Command Injection Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.983250000000; percentile 0.999110000000

Applicability

Cited product scope

Trace impact →
14Underlying assertions
14Canonical products
7Target assertions
7Constraint assertions

Grouped from 14 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.

Identity source boundaries
  • cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

15 scope groups

certcc · source assertedn/an/aDirect source scope
[{"status": "affected", "version": "n/a"}]
unknown
NVD CPE · HARDWAREnetgearwn604Environmental constraint · 1 assertions
Version not applicableCanonical identity product-1780981622bd1910eafa81b5f138916c4eed4565ac6283ba7f377dcae31aeedblinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:wn604:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd31dcaa-baa5-4463-9ea4-a7076a625407
NVD CPE · OPERATING SYSTEMnetgearwn604_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 3.3.2)Canonical identity product-01541bdf1b65a5aeb7e346c9bf046a11003e05d1dfff5b7e80ef32cf47563240linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:wn604_firmware:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 3.3.2
    Match ID
    8ca9cfc3-d7d5-4538-aa31-9c4504e5afa7
NVD CPE · HARDWAREnetgearwn802tv2Environmental constraint · 1 assertions
Version not applicableCanonical identity product-f5bcf6c06c74d269301c5e9444388a9204dad7be0928d97e2ec8fb705e9cbc98linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:wn802tv2:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    05b05670-cc01-4f53-b1a7-83fe3afba12e
NVD CPE · OPERATING SYSTEMnetgearwn802tv2_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-200172c4db86f8fbee4d4bd4d61f46969f0a67ead19a6c09225ce6065439105alinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:wn802tv2_firmware:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 3.0.5.0
    Match ID
    169f7661-bb39-4188-a26e-9791fce1da6b
NVD CPE · HARDWAREnetgearwnap320Environmental constraint · 1 assertions
Version not applicableCanonical identity product-04d90a6360cc087f00636b4e2fac753e960b117cd9c3d06c7494461994ea9722linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:wnap320:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5e2613e9-caf9-4c04-85bc-e10bdf4b0e74
NVD CPE · OPERATING SYSTEMnetgearwnap320_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-ec07f18a8dea4c0866a9c1bb6a7fa226ef82d549b462222479af1ee84441a4a6linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:wnap320_firmware:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 3.0.5.0
    Match ID
    cbce4d2f-5a11-4043-8f3e-4c10d155a6ed
NVD CPE · HARDWAREnetgearwndap210v2Environmental constraint · 1 assertions
Version not applicableCanonical identity product-273da0bd6682257ba5b4c0e0f928b549c8b11c1eb9538f9daf75089ac1d82862linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:wndap210v2:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5d1ad5a1-5212-4c0a-88bb-f34314f9c037
NVD CPE · OPERATING SYSTEMnetgearwndap210v2_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-87092b67260f991392701d7fa7e02d4864b4f1ddc6d872fd1d67c18532860635linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:wndap210v2_firmware:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 3.0.5.0
    Match ID
    9801e95c-9464-4594-b4e8-6f227c597c27
NVD CPE · HARDWAREnetgearwndap350Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d539a65f1861f15a9b8cf2ebc2ce1650fd84b4f47129b89598ae5b10512eaf46linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:wndap350:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c82a16c2-dc48-4792-a4c7-8ac43f84196d
NVD CPE · OPERATING SYSTEMnetgearwndap350_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-79d835119e429b503ca1b3bd7559c83b0a44839a407a8c64b6a76e69bac7cfb9linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:wndap350_firmware:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 3.0.5.0
    Match ID
    cb422d25-d72d-445b-869d-4a5fbf285357
NVD CPE · HARDWAREnetgearwndap360Environmental constraint · 1 assertions
Version not applicableCanonical identity product-a57901335748a0666b8084d869d9dd8b1c3ce70644f8e336dfd7c4b0067ed736linked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:wndap360:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7975d6ec-1816-4d52-8c87-77c1b6404120
NVD CPE · OPERATING SYSTEMnetgearwndap360_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-756749d336f7d5e4da0946cda8148f0c5635485b69e0ea2a7931d45cdb7933dflinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:wndap360_firmware:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 3.0.5.0
    Match ID
    fa1e8f1e-ab78-4c4b-be0b-ae17e4636077
NVD CPE · HARDWAREnetgearwndap660Environmental constraint · 1 assertions
Version not applicableCanonical identity product-8d4b687fc5968567f112b64bd7534a2ec8e1ef957f9c2d4a24dd31d85cbd55ddlinked exact
constrained
Inspect 1 returned assertions
  1. cpe:2.3:h:netgear:wndap660:-:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    58d2492e-0cdc-4242-9206-7f0453b11cbd
NVD CPE · OPERATING SYSTEMnetgearwndap660_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 3.0.5.0)Canonical identity product-925e19a92ab6d361ca52b79c01c96e7fff7868a1cebb9a842d3bb78110169ca7linked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:netgear:wndap660_firmware:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 3.0.5.0
    Match ID
    99e67c3d-8907-4a96-bbaa-128959db3962

Assessments

CVSS by origin

9.8
nvd@nist.govCVSS 3.1 · role PrimaryCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
nvd@nist.govCVSS 2.0 · role PrimaryAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.