CVE-2016-5675: Input Validation
handledaylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5675?
CVE-2016-5675 has a medium severity rating due to the potential for remote code execution.
How do I fix CVE-2016-5675?
To mitigate CVE-2016-5675, upgrade your affected NUUO or NETGEAR devices to the latest software version provided by the vendor.
Which devices are affected by CVE-2016-5675?
CVE-2016-5675 affects NUUO NVRmini 2, NVRsolo, Crystal, and NETGEAR ReadyNAS Surveillance models running specific versions.
What kind of attack can exploit CVE-2016-5675?
CVE-2016-5675 can be exploited by remote attackers to execute arbitrary PHP code by crafting specific input to the NTPServer parameter.
Is CVE-2016-5675 actively being exploited?
There have been reports indicating that CVE-2016-5675 is being actively exploited in the wild, necessitating prompt action from affected users.