VYPR
Unrated severityNVD Advisory· Published Apr 28, 2020· Updated Aug 6, 2024

CVE-2016-11060

CVE-2016-11060

Description

Certain NETGEAR devices are affected by insecure renegotiation. This affects SRX5308 before 2017-02-10, FVS336Gv3 before 2017-02-10, FVS318N before 2017-02-10, and FVS318Gv2 before 2017-02-10.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR firewalls SRX5308, FVS336Gv3, FVS318N, and FVS318Gv2 are vulnerable to denial of service via insecure SSL renegotiation before firmware 4.3.4-2.

Vulnerability

NETGEAR firewalls SRX5308, FVS336Gv3, FVS318N, and FVS318Gv2 running firmware versions prior to 4.3.4-2 (released before 2017-02-10) are affected by an insecure renegotiation vulnerability in their SSL/TLS implementation [1]. The bug allows a client to insecurely renegotiate a remote connection after the initial handshake, bypassing normal security controls.

Exploitation

An unauthenticated remote attacker can exploit this vulnerability by establishing an SSL/TLS connection to the affected device and then repeatedly requesting renegotiation of the session [1]. No prior authentication or special network position is required; the attacker only needs network access to the device's management interface or other SSL/TLS services.

Impact

Successful exploitation leads to a denial of service (DoS) condition, as the device's resources are consumed by handling excessive renegotiation requests [1]. The attack affects availability but does not result in information disclosure or remote code execution.

Mitigation

NETGEAR released firmware version 4.3.4-2 to fix this vulnerability [1]. Users should update their devices to this version or later. No workarounds are documented. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.