CVE-2016-5675
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 70.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 70.88% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- netgear/readynas surveillance · nuuo/crystal · nuuo/nvrsolo · nuuo/nvrmini 2
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/856152Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/92318
- https://www.exploit-db.com/exploits/40200/
- http://www.kb.cert.org/vuls/id/856152Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/92318
- https://www.exploit-db.com/exploits/40200/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.