Vulnerability record · CVE-2016-5674 · published 31 August 2016
CVE-2016-5674: NUUO NVR and NETGEAR ReadyNAS Surveillance PHP code execution via log parameter
Netgear · Readynas Surveillance
The __debugging_center_utils___.php script in NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance fails to validate the log parameter, allowing remote attackers to inject and execute arbitrary PHP code. Because the endpoint is network-reachable and needs no credentials, any exposed device is at risk of full compromise.
Description
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a public exploit and near-maximum EPSS probability on internet-exposed surveillance and storage devices.
What it is
The __debugging_center_utils___.php script in NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance fails to validate the log parameter, allowing remote attackers to inject and execute arbitrary PHP code. Because the endpoint is network-reachable and needs no credentials, any exposed device is at risk of full compromise.
Impact
An unauthenticated attacker gains arbitrary PHP code execution on the device, which typically means full control of the NVR or NAS, including stored video, credentials and any data it can reach.
Attack surface
Reached over the network through the __debugging_center_utils___.php endpoint; the CVSS vector shows no privileges and no user interaction required, so the request can be sent directly to the web interface.
Exploitation
A public Exploit-DB entry (40200) exists, and EPSS is 0.9461 (99.85th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Apply the vendor fix or the CERT/CC-recommended update for NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance; if no patch is available, retire or replace the affected device.
- Remove or block access to __debugging_center_utils___.php and other debugging endpoints at the web server or reverse proxy.
- Never expose the device management interface to the internet; restrict it to a dedicated management VLAN with allowlisted source addresses.
- Rotate credentials and review stored data on any device that may have been exposed, since code execution implies full device compromise.
Detection
- Search web logs for requests to __debugging_center_utils___.php, especially with a log parameter containing PHP tags or function calls.
- Alert on unexpected PHP file creation or modification in the device webroot and on outbound connections from the NVR/NAS to unfamiliar hosts.
- Monitor for new or altered admin accounts, cron entries or startup scripts on the affected appliances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.kb.cert.org/vuls/id/856152 | Third Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/92318 | |
| https://www.exploit-db.com/exploits/40200/ | |
| http://www.kb.cert.org/vuls/id/856152 | Third Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/92318 | |
| https://www.exploit-db.com/exploits/40200/ |
Track CVE-2016-5674 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-5674), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.