CVE-2016-5680: Buffer Overflow
Published Aug 31, 2016
·Updated
Stack-based buffer overflow in cgi-bin/cgimain in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn parameter to the transferlicense command.
Affected Software
5 affected components
NUUO NVRmini 2=1.7.6
NUUO NVRmini 2=2.0.0
NUUO NVRmini 2=2.2.1
NUUO NVRmini 2=3.0.0
Netgear ReadyNAS Surveillance=1.1.2
Event History
Aug 31, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5680?
CVE-2016-5680 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2016-5680?
To fix CVE-2016-5680, update NUUO NVRmini 2 to version 3.0.1 or later or NETGEAR ReadyNAS Surveillance to a patched version.
3
Who is affected by CVE-2016-5680?
CVE-2016-5680 affects NUUO NVRmini 2 versions 1.7.6 to 3.0.0 and NETGEAR ReadyNAS Surveillance version 1.1.2.
4
What kind of attack does CVE-2016-5680 enable?
CVE-2016-5680 allows authenticated remote users to execute arbitrary code on the affected devices.
5
When was CVE-2016-5680 discovered?
CVE-2016-5680 was published in August 2016.