← Back

CVE-2016-5675

nvd nist
Published: Aug 31, 2016Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.

Affected (36)

1 product
Readynas Surveillance
3 products
Crystal
Nvrsolo
Nvrmini 2
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Netgear
Version 1.1.1
Version 1.1.2
Version 1.2.0.4
Version 1.3.2.14
Version 1.3.2.4
Version 1.4.0
Version 1.4.1
Version 1.4.2
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Nuuo
Version 2.2.1
Version 3.0.0
Version 3.1.0
Version 3.2.0
Configuration C
19 vulnerable
Vulnerable SoftwareAffected Versions
Nuuo
Version 1.0.0
Version 1.0.1
Version 1.1.0.117
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.2.0
Version 1.3.0
Version 1.75
Version 2.0.0
Version 2.0.1
Version 2.1.5
Version 2.2.2
Version 2.3.1.20
Version 2.3.7.10
Version 2.3.7.9
Version 2.3.9.6
Version 2.3
Version 3.0.0
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
Nuuo
Version 1.7.5
Version 1.7.6
Version 2.0.0
Version 2.2.1
Version 3.0.0

References (6)

Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.