peter bassill · operator
$ cve CVE-2016-1524 JSON

CVE-2016-1524 EXPLOIT

9.6
CRITICAL · CVSS 3.0 · EPSS 94.1% (pctl 100)

Patch early

A public exploit exists.

Description

Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.

Scoring

CVSS9.6 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS94.1% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2016-02-13
Last modified2026-06-17

Affected (1)

VendorProduct
netgearprosafe network management software 300

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD