First published: Wed Aug 31 2016(Updated: )
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Readynas Surveillance Firmware | =1.1.1 | |
Netgear Readynas Surveillance Firmware | =1.1.2 | |
Netgear Readynas Surveillance Firmware | =1.2.0.4 | |
Netgear Readynas Surveillance Firmware | =1.3.2.4 | |
Netgear Readynas Surveillance Firmware | =1.3.2.14 | |
Netgear Readynas Surveillance Firmware | =1.4.0 | |
Netgear Readynas Surveillance Firmware | =1.4.1 | |
Netgear Readynas Surveillance Firmware | =1.4.2 | |
NUUO Crystal | =2.2.1 | |
NUUO Crystal | =3.0.0 | |
NUUO Crystal | =3.1.0 | |
NUUO Crystal | =3.2.0 | |
Nuuo NVRsolo Firmware | =1.0.0 | |
Nuuo NVRsolo Firmware | =1.0.1 | |
Nuuo NVRsolo Firmware | =1.1.0 | |
Nuuo NVRsolo Firmware | =1.1.0.117 | |
Nuuo NVRsolo Firmware | =1.1.1 | |
Nuuo NVRsolo Firmware | =1.1.2 | |
Nuuo NVRsolo Firmware | =1.2.0 | |
Nuuo NVRsolo Firmware | =1.3.0 | |
Nuuo NVRsolo Firmware | =1.75 | |
Nuuo NVRsolo Firmware | =2.0.0 | |
Nuuo NVRsolo Firmware | =2.0.1 | |
Nuuo NVRsolo Firmware | =2.1.5 | |
Nuuo NVRsolo Firmware | =2.2.2 | |
Nuuo NVRsolo Firmware | =2.3 | |
Nuuo NVRsolo Firmware | =2.3.1.20 | |
Nuuo NVRsolo Firmware | =2.3.7.9 | |
Nuuo NVRsolo Firmware | =2.3.7.10 | |
Nuuo NVRsolo Firmware | =2.3.9.6 | |
Nuuo NVRsolo Firmware | =3.0.0 | |
Nuuo NVRmini 2 Firmware | =1.7.5 | |
Nuuo NVRmini 2 Firmware | =1.7.6 | |
Nuuo NVRmini 2 Firmware | =2.0.0 | |
Nuuo NVRmini 2 Firmware | =2.2.1 | |
Nuuo NVRmini 2 Firmware | =3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5675 has a medium severity rating due to the potential for remote code execution.
To mitigate CVE-2016-5675, upgrade your affected NUUO or NETGEAR devices to the latest software version provided by the vendor.
CVE-2016-5675 affects NUUO NVRmini 2, NVRsolo, Crystal, and NETGEAR ReadyNAS Surveillance models running specific versions.
CVE-2016-5675 can be exploited by remote attackers to execute arbitrary PHP code by crafting specific input to the NTPServer parameter.
There have been reports indicating that CVE-2016-5675 is being actively exploited in the wild, necessitating prompt action from affected users.