CVE-2016-5676: High severity netgear readynas surveillance firmware vulnerability
cgi-bin/cgisystem in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5676?
CVE-2016-5676 is considered a medium severity vulnerability due to its potential impact on security by allowing unauthorized password resets.
How do I fix CVE-2016-5676?
To fix CVE-2016-5676, users should upgrade to the latest version of the affected software that addresses this vulnerability.
Which software is affected by CVE-2016-5676?
CVE-2016-5676 affects NUUO NVRmini 2 versions 1.7.5 through 2.x, NUUO NVRsolo versions 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance versions 1.1.1 through 1.4.1.
Can the CVE-2016-5676 vulnerability be exploited remotely?
Yes, CVE-2016-5676 can be exploited remotely by attackers to reset administrator passwords.
What actions should I take if I use software affected by CVE-2016-5676?
If you use software affected by CVE-2016-5676, you should assess your exposure and implement necessary updates or mitigations immediately.