← Vulnerability feed

Vulnerability record · CVE-2016-1524 · published 13 February 2016

CVE-2016-1524: NETGEAR NMS300 unrestricted file upload leads to Java code execution

Netgear · Prosafe Network Management Software 300

NETGEAR Management System NMS300 1.5.0.11 and earlier exposes multiple unrestricted file upload endpoints (fileUpload.do and lib-1.0/external/flash/fileUpload.do) that accept a JSP file without validating its type. An attacker can upload that JSP and then request it through a /null URI to run arbitrary Java code on the server.

9.6 CVSS 3.0 Critical EPSS 94% · top 0.2%
9.6CVSS 3.0 base score, v2 8.3
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a critical CVSS score of 9.6 and very high EPSS probability, with public exploit code available.

What it is

NETGEAR Management System NMS300 1.5.0.11 and earlier exposes multiple unrestricted file upload endpoints (fileUpload.do and lib-1.0/external/flash/fileUpload.do) that accept a JSP file without validating its type. An attacker can upload that JSP and then request it through a /null URI to run arbitrary Java code on the server.

Impact

Successful exploitation gives the attacker remote code execution in the context of the NMS300 application server, allowing full compromise of the management host and any data or managed devices it controls.

Attack surface

The flaw is reached over the network via the web management interface on the two upload endpoints; the CVSS vector (AV:A) indicates the attacker must be on an adjacent network segment, and no authentication or user interaction is required.

Exploitation

CVE-2016-1524 is not listed in CISA KEV, but EPSS is very high (0.941, 99.8th percentile) and public exploit code exists on Exploit-DB (39412) and Packet Storm, so exploitation is practical and likely.

What to do

  • Upgrade NMS300 to a version later than 1.5.0.11 if NETGEAR provides one; treat the product as end-of-life and plan replacement if no fix exists.
  • Restrict network access to the NMS300 web interface so only trusted administrative hosts on a dedicated management VLAN can reach it.
  • Block or reject requests to fileUpload.do and lib-1.0/external/flash/fileUpload.do at a reverse proxy or WAF, and deny direct access to uploaded files.
  • Disable or remove the Flash-based upload component if it is not required for operations.
  • Monitor and alert on unexpected JSP files appearing in web-accessible directories.

Detection

  • Review web server and application logs for POST requests to fileUpload.do or lib-1.0/external/flash/fileUpload.do, especially from unexpected source addresses.
  • Search the NMS300 web root and upload directories for newly created .jsp files and alert on any such file.
  • Monitor for requests to /null URIs or other direct requests to uploaded files that return executable content.
  • Baseline normal administrative traffic to the NMS300 interface and alert on upload activity outside maintenance windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-1524 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2016-1524), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.