VYPR
High severity8.6NVD Advisory· Published Dec 27, 2015· Updated May 6, 2026

CVE-2015-8263

CVE-2015-8263

Description

NETGEAR WNR1000v3 routers use a static source port for all DNS queries, enabling remote attackers to spoof DNS responses.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR WNR1000v3 routers use a static source port for all DNS queries, enabling remote attackers to spoof DNS responses.

Vulnerability

The NETGEAR WNR1000v3 wireless router running firmware version 1.0.2.68 (and possibly earlier) uses a static source port for all DNS queries originating from the local area network. This violates the principle of using random source ports to prevent DNS spoofing attacks [1].

Exploitation

An attacker with the ability to spoof DNS responses can exploit this weakness by predicting the static source port number. No authentication is required, and the attack can be launched remotely. The attacker simply monitors or knows the fixed port, then sends a forged DNS response to that port, which the router will accept as valid [1].

Impact

Successful exploitation allows the attacker to redirect LAN clients to attacker-controlled hosts. This can lead to traffic interception, phishing, malware distribution, or other malicious activities, compromising the confidentiality and integrity of network communications [1].

Mitigation

As of the publication date, the CERT/CC is not aware of a practical solution. No firmware update or workaround has been released by NETGEAR. Users are advised to monitor for future patches or consider replacing the device if security is critical [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Netgear/WNR1000v32 versions
    cpe:2.3:h:netgear:wnr1000v3:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:h:netgear:wnr1000v3:*:*:*:*:*:*:*:*
    • (no CPE)range: = 1.0.2.68
  • cpe:2.3:o:netgear:wnr1000v3_firmware:1.0.2.68:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.