First published: Wed Aug 31 2016(Updated: )
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR ReadyNAS Surveillance | =1.1.1 | |
NETGEAR ReadyNAS Surveillance | =1.1.2 | |
NETGEAR ReadyNAS Surveillance | =1.2.0.4 | |
NETGEAR ReadyNAS Surveillance | =1.3.2.4 | |
NETGEAR ReadyNAS Surveillance | =1.3.2.14 | |
NETGEAR ReadyNAS Surveillance | =1.4.0 | |
NETGEAR ReadyNAS Surveillance | =1.4.1 | |
NETGEAR ReadyNAS Surveillance | =1.4.2 | |
NUUO NVRmini 2 | =1.7.5 | |
NUUO NVRmini 2 | =1.7.6 | |
NUUO NVRmini 2 | =2.0.0 | |
NUUO NVRmini 2 | =2.2.1 | |
NUUO NVRmini 2 | =3.0.0 | |
NUUO NVRsolo | =1.75 | |
NUUO NVRsolo | =2.0.0 | |
NUUO NVRsolo | =2.0.1 | |
NUUO NVRsolo | =2.1.5 | |
NUUO NVRsolo | =2.2.2 | |
NUUO NVRsolo | =2.3 | |
NUUO NVRsolo | =2.3.1.20 | |
NUUO NVRsolo | =2.3.7.9 | |
NUUO NVRsolo | =2.3.7.10 | |
NUUO NVRsolo | =2.3.9.6 | |
NUUO NVRsolo | =3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5674 has a severity rating that indicates a critical risk due to its potential for arbitrary PHP code execution.
To fix CVE-2016-5674, you should upgrade to the latest versions of NETGEAR ReadyNAS Surveillance and NUUO NVR products that are not affected by this vulnerability.
CVE-2016-5674 affects NUUO NVRmini 2 versions 1.7.5 through 3.0.0, NUUO NVRsolo versions 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance versions 1.1.1 through 1.4.1.
CVE-2016-5674 allows remote attackers to execute arbitrary PHP code, potentially compromising the affected systems.
Yes, there are known exploits associated with CVE-2016-5674 that can take advantage of the vulnerability to execute unauthorized actions.