CVE-2016-5675 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 70.9% (pctl 99)
Patch early
A public exploit exists.
Description
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 70.88% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-08-31 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| netgear | readynas surveillance |
| nuuo | crystal |
| nuuo | nvrmini 2 |
| nuuo | nvrsolo |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | 2016-08-05 |
References
→ the Explorer · watch your stack · NVD