VYPR
Unrated severityNVD Advisory· Published Apr 28, 2020· Updated Aug 6, 2024

CVE-2016-11055

CVE-2016-11055

Description

Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 before 2017-01-11, JWNR2000Tv3 before 2017-01-11, JWNR2010v3 before 2017-01-11, PLW1000 before 2017-01-11, PLW1010 before 2017-01-11, WNR500 before 2017-01-11, WNR612v3 before 2017-01-11, N450 before 2017-01-11, and CG3000Dv2 before 2017-01-11.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in multiple NETGEAR devices before firmware update 2017-01-11 allows attackers to change router settings via malicious scripts.

Vulnerability

A cross-site request forgery (CSRF) vulnerability exists in numerous NETGEAR devices, including CM400, CM600, D1500, D500, DST6501, JNR1010v1, JWNR2000Tv3, JWNR2010v3, PLW1000, PLW1010, WNR500, WNR612v3, N450, and CG3000Dv2, in firmware versions before 2017-01-11 [1]. The flaw allows an attacker to forge requests that execute unintended actions on the device.

Exploitation

An attacker can exploit this CSRF by tricking an authenticated administrator into visiting a malicious website or clicking a crafted link. If the victim is currently logged into the router's web interface, the attacker's script can automatically send requests to change device settings without the victim's knowledge [1]. No authentication or network access is required beyond the victim's active session.

Impact

Successful exploitation enables the attacker to modify router configuration as if they were the administrator. For routers, this could allow remote access to the private network and compromise data confidentiality and integrity. For affected Powerline adapters (PLW1000, PLW1010), only adapter settings can be altered, not the private network [1].

Mitigation

NETGEAR has released firmware fixes for all affected models, available on the product support pages [1]. Users should update their device firmware to a version dated after 2017-01-11. For cable products like the N450 (CG3000Dv2), updates are distributed by the Internet service provider. No workaround is available other than applying the firmware update [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.