{
    "id": "CVE-2016-5675",
    "published": "2016-08-31 15:59:01",
    "last_modified": "2026-06-17 00:49:51",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-20",
    "description": "handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.",
    "epss_score": "0.70877",
    "epss_percentile": "0.99383",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:20:40",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "netgear",
            "product": "readynas_surveillance"
        },
        {
            "vendor": "nuuo",
            "product": "crystal"
        },
        {
            "vendor": "nuuo",
            "product": "nvrmini_2"
        },
        {
            "vendor": "nuuo",
            "product": "nvrsolo"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "40200",
            "title": "NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities",
            "date": "2016-08-05",
            "url": "https://www.exploit-db.com/exploits/40200"
        }
    ],
    "refs_list": [
        "http://www.kb.cert.org/vuls/id/856152",
        "http://www.securityfocus.com/bid/92318",
        "https://www.exploit-db.com/exploits/40200/",
        "http://www.kb.cert.org/vuls/id/856152",
        "http://www.securityfocus.com/bid/92318",
        "https://www.exploit-db.com/exploits/40200/"
    ]
}