peter bassill · operator
$ cve CVE-2016-5675 JSON

CVE-2016-5675 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 70.9% (pctl 99)

Patch early

A public exploit exists.

Description

handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS70.88% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2016-08-31
Last modified2026-06-17

Affected (4)

VendorProduct
netgearreadynas surveillance
nuuocrystal
nuuonvrmini 2
nuuonvrsolo

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD