CVE-2016-5674

EUVD-2016-6618
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
netgearreadynas_surveillance
1.1.1
netgearreadynas_surveillance
1.1.2
netgearreadynas_surveillance
1.2.0.4
netgearreadynas_surveillance
1.3.2.4
netgearreadynas_surveillance
1.3.2.14
netgearreadynas_surveillance
1.4.0
netgearreadynas_surveillance
1.4.1
netgearreadynas_surveillance
1.4.2
nuuonvrmini_2
1.7.5
nuuonvrmini_2
1.7.6
nuuonvrmini_2
2.0.0
nuuonvrmini_2
2.2.1
nuuonvrmini_2
3.0.0
nuuonvrsolo
1.75
nuuonvrsolo
2.0.0
nuuonvrsolo
2.0.1
nuuonvrsolo
2.1.5
nuuonvrsolo
2.2.2
nuuonvrsolo
2.3
nuuonvrsolo
2.3.1.20
nuuonvrsolo
2.3.7.9
nuuonvrsolo
2.3.7.10
nuuonvrsolo
2.3.9.6
nuuonvrsolo
3.0.0
𝑥
= Vulnerable software versions