CVE-2016-5677
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 11.99% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- netgear/readynas surveillance · nuuo/nvrmini 2 · nuuo/nvrsolo
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/856152Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/92318
- https://www.exploit-db.com/exploits/40200/
- http://www.kb.cert.org/vuls/id/856152Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/92318
- https://www.exploit-db.com/exploits/40200/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.