← Back

CVE-2016-5677

nvd nist
Published: Aug 31, 2016Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request.

Affected (32)

1 product
Readynas Surveillance
2 products
Nvrmini 2
Nvrsolo
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Netgear
Version 1.1.1
Version 1.1.2
Version 1.2.0.4
Version 1.3.2.14
Version 1.3.2.4
Version 1.4.0
Version 1.4.1
Version 1.4.2
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Nuuo
Version 1.7.5
Version 1.7.6
Version 2.0.0
Version 2.2.1
Version 3.0.0
Configuration C
19 vulnerable
Vulnerable SoftwareAffected Versions
Nuuo
Version 1.0.0
Version 1.0.1
Version 1.1.0.117
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.2.0
Version 1.3.0
Version 1.75
Version 2.0.0
Version 2.0.1
Version 2.1.5
Version 2.2.2
Version 2.3.1.20
Version 2.3.7.10
Version 2.3.7.9
Version 2.3.9.6
Version 2.3
Version 3.0.0

References (6)

Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.