CVE-2016-1524: Critical severity netgear nms300 vulnerability
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1524?
CVE-2016-1524 is a critical vulnerability that allows remote attackers to execute arbitrary Java code due to unrestricted file upload vulnerabilities.
How do I fix CVE-2016-1524?
To fix CVE-2016-1524, users should upgrade to a patched version of NETGEAR Management System NMS300 that addresses the vulnerability.
What systems are affected by CVE-2016-1524?
CVE-2016-1524 affects NETGEAR ProSAFE Network Management Software 300 versions 1.5.0.11 and earlier.
What type of attack can be executed using CVE-2016-1524?
CVE-2016-1524 can be exploited by remote attackers to execute arbitrary code on the affected system.
What files can be uploaded due to CVE-2016-1524?
CVE-2016-1524 allows attackers to upload JSP files through specific file upload endpoints.