CVE-2016-5674

High PUBLISHED

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1...

Vendor: NUUO Product: ["NVRmini 2", "NVRsolo", "ReadyNAS Surveillance"]

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.8 Critical EPSS 94.6%

At a Glance

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.

metasploit php nuclei_scanner edge
CVE Published
Aug 31, 2016
Exploitation Reported
Apr 27, 2025
CVSS
9.8 Critical
EPSS
94.6%
Remote Low complexity No user interaction Unauthenticated

CVE References

  • VU#856152 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/856152
  • 40200 exploit-db.com · Exploit https://www.exploit-db.com/exploits/40200/
  • 92318 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/92318