KEVIntel
9.8
CVSS
Critical

CVE-2016-5674

PUBLISHED

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1...

Exploited in the wild Remote Low complexity No user interaction
Vendor
["NUUO", "NETGEAR"]
Product
["NVRmini 2", "NVRsolo", "ReadyNAS Surveillance"]
Published
Aug 31, 2016
EPSS

Description

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.

php nuclei_scanner edge metasploit

CVSS scores

CVSS v3.0 9.8 Critical

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 10.0

AV:N/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2025-04-27 00:00:00 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Apr 27, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

nuuo_nvrmini_unauth_rce

metasploit · Created Unknown

Metasploit module for CVE-2016-5674

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Added to KEVIntel

  • Detected by Metasploit