VYPR
Critical severity9.8NVD Advisory· Published Jul 24, 2018· Updated Jun 17, 2026

CVE-2016-5649

CVE-2016-5649

Description

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Netgear/DGND3700llm-fuzzy2 versions
    DGND3700-V1.0.0.17_1.0.17+ 1 more
    • (no CPE)range: DGND3700-V1.0.0.17_1.0.17
    • (no CPE)range: DGND3700-V1.0.0.17_1.0.17
  • Netgear/DGN2200llm-fuzzy
    Range: DGN2200-V1.0.0.50_7.0.50
  • Netgear/DGN2200v4cpe-rescue
    Range: DGN2200-V1.0.0.50_7.0.50

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.