CVE-2016-5675
EUVD-2016-661931.08.2016, 15:59
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| netgear | readynas_surveillance | 1.1.1 |
| netgear | readynas_surveillance | 1.1.2 |
| netgear | readynas_surveillance | 1.2.0.4 |
| netgear | readynas_surveillance | 1.3.2.4 |
| netgear | readynas_surveillance | 1.3.2.14 |
| netgear | readynas_surveillance | 1.4.0 |
| netgear | readynas_surveillance | 1.4.1 |
| netgear | readynas_surveillance | 1.4.2 |
| nuuo | crystal | 2.2.1 |
| nuuo | crystal | 3.0.0 |
| nuuo | crystal | 3.1.0 |
| nuuo | crystal | 3.2.0 |
| nuuo | nvrsolo | 1.0.0 |
| nuuo | nvrsolo | 1.0.1 |
| nuuo | nvrsolo | 1.1.0 |
| nuuo | nvrsolo | 1.1.0.117 |
| nuuo | nvrsolo | 1.1.1 |
| nuuo | nvrsolo | 1.1.2 |
| nuuo | nvrsolo | 1.2.0 |
| nuuo | nvrsolo | 1.3.0 |
| nuuo | nvrsolo | 1.75 |
| nuuo | nvrsolo | 2.0.0 |
| nuuo | nvrsolo | 2.0.1 |
| nuuo | nvrsolo | 2.1.5 |
| nuuo | nvrsolo | 2.2.2 |
| nuuo | nvrsolo | 2.3 |
| nuuo | nvrsolo | 2.3.1.20 |
| nuuo | nvrsolo | 2.3.7.9 |
| nuuo | nvrsolo | 2.3.7.10 |
| nuuo | nvrsolo | 2.3.9.6 |
| nuuo | nvrsolo | 3.0.0 |
| nuuo | nvrmini_2 | 1.7.5 |
| nuuo | nvrmini_2 | 1.7.6 |
| nuuo | nvrmini_2 | 2.0.0 |
| nuuo | nvrmini_2 | 2.2.1 |
| nuuo | nvrmini_2 | 3.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration