CVE-2016-5675: NETGEAR Readynas Surveillance
Critical severity, CVSS 9.8. EPSS: 70.9% chance of exploitation in the next 30 days.
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
Affected products
- NETGEAR Readynas Surveillance: version 1.1.1 only; version 1.1.2 only; version 1.2.0.4 only; version 1.3.2.4 only; version 1.3.2.14 only; version 1.4.0 only; …
- NUUO Crystal: version 2.2.1 only; version 3.0.0 only; version 3.1.0 only; version 3.2.0 only
- NUUO NVRmini 2: version 1.7.5 only; version 1.7.6 only; version 2.0.0 only; version 2.2.1 only; version 3.0.0 only
- NUUO Nvrsolo: version 1.0.0 only; version 1.0.1 only; version 1.1.0 only; version 1.1.0.117 only; version 1.1.1 only; version 1.1.2 only; …
Published 2016-08-31. Last modified 2026-06-17.