CVE-2016-11060
Description
Certain NETGEAR devices are affected by insecure renegotiation. This affects SRX5308 before 2017-02-10, FVS336Gv3 before 2017-02-10, FVS318N before 2017-02-10, and FVS318Gv2 before 2017-02-10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NETGEAR firewalls SRX5308, FVS336Gv3, FVS318N, and FVS318Gv2 are vulnerable to denial of service via insecure SSL renegotiation before firmware 4.3.4-2.
Vulnerability
NETGEAR firewalls SRX5308, FVS336Gv3, FVS318N, and FVS318Gv2 running firmware versions prior to 4.3.4-2 (released before 2017-02-10) are affected by an insecure renegotiation vulnerability in their SSL/TLS implementation [1]. The bug allows a client to insecurely renegotiate a remote connection after the initial handshake, bypassing normal security controls.
Exploitation
An unauthenticated remote attacker can exploit this vulnerability by establishing an SSL/TLS connection to the affected device and then repeatedly requesting renegotiation of the session [1]. No prior authentication or special network position is required; the attacker only needs network access to the device's management interface or other SSL/TLS services.
Impact
Successful exploitation leads to a denial of service (DoS) condition, as the device's resources are consumed by handling excessive renegotiation requests [1]. The attack affects availability but does not result in information disclosure or remote code execution.
Mitigation
NETGEAR released firmware version 4.3.4-2 to fix this vulnerability [1]. Users should update their devices to this version or later. No workarounds are documented. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- kb.netgear.com/31426/SSL-Renegotiation-Denial-of-Service-Vulnerabilitymitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.