CVE-2016-10116
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain access via a dictionary attack.
Published:Jan 4, 2017
Last Modified:Apr 12, 2025
EPS:Jan 4, 2017
EPSS Score:0.0709
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Netgear
Product
Arlo Base Station Firmware
Netgear
Arlo Base Station Firmware
Vendor
Netgear
Product
Arlo Q Camera Firmware
Netgear
Arlo Q Camera Firmware
Vendor
Netgear
Product
Arlo Q Plus Camera Firmware
Netgear
Arlo Q Plus Camera Firmware
Vendor
Netgear
Product
Vmb30x0
Netgear
Vmb30x0
Vendor
Netgear
Product
Vmc3040
Netgear
Vmc3040
Vendor
Netgear
Product
Vmc3040s
Netgear
Vmc3040s
Vendor
Netgear
Product
Vmk3xx0
Netgear
Vmk3xx0
Vendor
Netgear
Product
Vms3xx0
Netgear
Vms3xx0
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
