← Vulnerability feed

Vulnerability record · CVE-2016-5674 · published 31 August 2016

CVE-2016-5674: NUUO NVR and NETGEAR ReadyNAS Surveillance PHP code execution via log parameter

Netgear · Readynas Surveillance

The __debugging_center_utils___.php script in NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance fails to validate the log parameter, allowing remote attackers to inject and execute arbitrary PHP code. Because the endpoint is network-reachable and needs no credentials, any exposed device is at risk of full compromise.

9.8 CVSS 3.0 Critical EPSS 95% · top 0.1% CWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 10.0
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a public exploit and near-maximum EPSS probability on internet-exposed surveillance and storage devices.

What it is

The __debugging_center_utils___.php script in NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance fails to validate the log parameter, allowing remote attackers to inject and execute arbitrary PHP code. Because the endpoint is network-reachable and needs no credentials, any exposed device is at risk of full compromise.

Impact

An unauthenticated attacker gains arbitrary PHP code execution on the device, which typically means full control of the NVR or NAS, including stored video, credentials and any data it can reach.

Attack surface

Reached over the network through the __debugging_center_utils___.php endpoint; the CVSS vector shows no privileges and no user interaction required, so the request can be sent directly to the web interface.

Exploitation

A public Exploit-DB entry (40200) exists, and EPSS is 0.9461 (99.85th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.

What to do

  • Apply the vendor fix or the CERT/CC-recommended update for NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance; if no patch is available, retire or replace the affected device.
  • Remove or block access to __debugging_center_utils___.php and other debugging endpoints at the web server or reverse proxy.
  • Never expose the device management interface to the internet; restrict it to a dedicated management VLAN with allowlisted source addresses.
  • Rotate credentials and review stored data on any device that may have been exposed, since code execution implies full device compromise.

Detection

  • Search web logs for requests to __debugging_center_utils___.php, especially with a log parameter containing PHP tags or function calls.
  • Alert on unexpected PHP file creation or modification in the device webroot and on outbound connections from the NVR/NAS to unfamiliar hosts.
  • Monitor for new or altered admin accounts, cron entries or startup scripts on the affected appliances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-5674 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-5678Nuuo nvrmini 2 hard-coded credentials vulnerabilityNUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain admi…EPSS 8.7%9.8CVE-2016-5675NUUO and NETGEAR NVR software PHP code execution via NTPServer parameterhandle_daylightsaving.php in NUUO NVRmini 2, NVRsolo, Crystal, and NETGEAR ReadyNAS Surveillance fails to validate the NTPServer parameter, allowing …EPSS 71%analysed8.8CVE-2016-11056Netgear readynas surveillance vulnerabilityCertain NETGEAR devices are affected by anonymous root access. This affects ReadyNAS Surveillance 1.1.1-3-armel and earlier and ReadyNAS Surveillance…EPSS 1.6%8.8CVE-2016-5680Nuuo nvrmini 2 memory buffer overflow vulnerabilityStack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authentic…EPSS 17%8.8CVE-2016-5679Nuuo nvrmini 2 os command injection vulnerabilitycgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary…EPSS 14%8.0CVE-2017-18861Netgear readynas surveillance cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects ReadyNAS Surveillance 1.4.3-15-x86 and earlier and ReadyNAS Surveillance 1.1.4-5-ARM and e…EPSS 0.38%7.5CVE-2016-5677Netgear readynas surveillance information exposure vulnerabilityNUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622…EPSS 12%7.5CVE-2016-5676NUUO NVR and NETGEAR ReadyNAS Surveillance admin password reset via improper authorizationThe cgi-bin/cgi_system endpoint in NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance accepts a cmd=loaddefconfig action that resets the admin…EPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2016-5674), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.