CVE-2016-1524 EXPLOIT
9.6
CRITICAL · CVSS 3.0 · EPSS 94.1% (pctl 100)
Patch early
A public exploit exists.
Description
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.
Scoring
| CVSS | 9.6 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 94.1% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-02-13 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| netgear | prosafe network management software 300 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Netgear NMS300 ProSafe Network Management System - Multiple Vulnerabilities | 2016-02-04 |
References
- http://packetstormsecurity.com/files/135618/Netgear-Pro-NMS-300-Code-Execution-File-Download.html
- http://seclists.org/fulldisclosure/2016/Feb/30
- http://www.kb.cert.org/vuls/id/777024
- http://www.securityfocus.com/archive/1/537446/100/0/threaded
- https://www.exploit-db.com/exploits/39412/
- http://packetstormsecurity.com/files/135618/Netgear-Pro-NMS-300-Code-Execution-File-Download.html
- http://seclists.org/fulldisclosure/2016/Feb/30
- http://www.kb.cert.org/vuls/id/777024
- http://www.securityfocus.com/archive/1/537446/100/0/threaded
- https://www.exploit-db.com/exploits/39412/
→ the Explorer · watch your stack · NVD