Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2016-5679

HIGH · 8.8 CVSS Gepubliceerd: CWE-78

Beschrijving NL

cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 t/m 3.0.0 en NETGEAR ReadyNAS Surveillance 1.1.2 stelt op afstand geverifieerde gebruikers in staat om willekeurige opdrachten uit te voeren via shell-metakarakters in de parameter sn naar de opdracht transfer_license.

Origineel (Engels) tonen

cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_license command.

Vendors

Nuuo Netgear

Affected products

Nvrmini 2 Readynas Surveillance

References