CVE-2016-5679: OS Command Injection
cgi-bin/cgimain in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transferlicense command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5679?
CVE-2016-5679 has a medium severity rating due to the ability for remote authenticated users to execute arbitrary commands.
How do I fix CVE-2016-5679?
To address CVE-2016-5679, users should upgrade to the latest versions of NUUO NVRmini 2 or NETGEAR ReadyNAS Surveillance that include patches.
What software is affected by CVE-2016-5679?
CVE-2016-5679 affects NUUO NVRmini 2 versions 1.7.6 to 3.0.0 and NETGEAR ReadyNAS Surveillance version 1.1.2.
Who is vulnerable to CVE-2016-5679?
Users of NUUO NVRmini 2 or NETGEAR ReadyNAS Surveillance within the specified versions are vulnerable to CVE-2016-5679.
What can attackers do with CVE-2016-5679?
Attackers exploiting CVE-2016-5679 can execute arbitrary commands on the affected devices via shell metacharacters.