CVE-2016-5649

Public Exploit
Netgear DGN2200 and DGND3700 disclose the administrator password

Description

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface.

Remediation

Solution:

  • Netgear has released firmware version 1.0.0.52 for DGN2200 & 1.0.0.28 for DGND3700 to address this issue.

Categories

9.8
CVSS
Severity: Critical
CVSS 3.0 •
CVSS 2.0 •
EPSS 76.98% Top 5%
Third-Party Advisory packetstormsecurity.com Third-Party Advisory packetstormsecurity.com
Affected: Netgear DGN2200
Affected: Netgear DGND3700
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2016-5649?
CVE-2016-5649 has been scored as a critical severity vulnerability.
How to fix CVE-2016-5649?
To fix CVE-2016-5649: Netgear has released firmware version 1.0.0.52 for DGN2200 & 1.0.0.28 for DGND3700 to address this issue.
Is CVE-2016-5649 being actively exploited in the wild?
It is possible that CVE-2016-5649 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~77% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2016-5649?
CVE-2016-5649 affects Netgear DGN2200, Netgear DGND3700.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.