CVE-2016-5679: NETGEAR Readynas Surveillance

High severity, CVSS 8.8. EPSS: 14.1% chance of exploitation in the next 30 days.

cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_license command.

Affected products

  • NETGEAR Readynas Surveillance: version 1.1.2 only
  • NUUO NVRmini 2: version 1.7.6 only; version 2.0.0 only; version 2.2.1 only; version 3.0.0 only

Published 2016-08-31. Last modified 2026-06-17.