← Vulnerability feed

Vulnerability record · CVE-2016-5675 · published 31 August 2016

CVE-2016-5675: NUUO and NETGEAR NVR software PHP code execution via NTPServer parameter

Netgear · Readynas Surveillance

handle_daylightsaving.php in NUUO NVRmini 2, NVRsolo, Crystal, and NETGEAR ReadyNAS Surveillance fails to validate the NTPServer parameter, allowing injection of arbitrary PHP code. Because the affected devices are network video recorders, successful exploitation gives an attacker code execution on a system that often sits on the camera network and holds recorded footage.

9.8 CVSS 3.0 Critical EPSS 71% · top 0.6% CWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 10.0
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code, and a very high EPSS score make this an urgent remote code execution risk on internet- or network-exposed NVR appliances.

What it is

handle_daylightsaving.php in NUUO NVRmini 2, NVRsolo, Crystal, and NETGEAR ReadyNAS Surveillance fails to validate the NTPServer parameter, allowing injection of arbitrary PHP code. Because the affected devices are network video recorders, successful exploitation gives an attacker code execution on a system that often sits on the camera network and holds recorded footage.

Impact

An attacker gains remote arbitrary PHP code execution with the privileges of the web server, which on these appliances typically means full control of the device and access to stored video and configuration data.

Attack surface

Reachable over the network through the web interface's handle_daylightsaving.php endpoint; the CVSS vector shows no privileges or user interaction required, so the request can be sent directly to the exposed service.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.70877, 99.4th percentile) and a public Exploit-DB entry (40200) exists, indicating exploit code is available and exploitation is plausible.

What to do

  • Apply the vendor firmware updates for NUUO NVRmini 2, NVRsolo, Crystal and NETGEAR ReadyNAS Surveillance that address the NTPServer input handling.
  • If no patch is available for a given model, isolate the NVR web interface from untrusted networks and restrict access to a management VLAN.
  • Block or filter requests to handle_daylightsaving.php from untrusted sources at the perimeter or reverse proxy.
  • Replace end-of-life NVR models that no longer receive security fixes.
  • Audit NVR web server accounts and disable unused remote access features.

Detection

  • Monitor web logs for requests to handle_daylightsaving.php, especially with unusual or encoded NTPServer parameter values.
  • Alert on PHP process spawning unexpected child processes or writing files under the web root on NVR hosts.
  • Watch for outbound connections from NVR devices to unfamiliar hosts, which may indicate post-exploitation activity.
  • Review NVR configuration changes and new administrative accounts for signs of tampering.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-5675 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-5678Nuuo nvrmini 2 hard-coded credentials vulnerabilityNUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain admi…EPSS 8.7%9.8CVE-2016-5674NUUO NVR and NETGEAR ReadyNAS Surveillance PHP code execution via log parameterThe __debugging_center_utils___.php script in NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance fails to validate the log parameter, allowing…EPSS 95%analysed8.8CVE-2016-11056Netgear readynas surveillance vulnerabilityCertain NETGEAR devices are affected by anonymous root access. This affects ReadyNAS Surveillance 1.1.1-3-armel and earlier and ReadyNAS Surveillance…EPSS 1.6%8.8CVE-2016-5680Nuuo nvrmini 2 memory buffer overflow vulnerabilityStack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authentic…EPSS 17%8.8CVE-2016-5679Nuuo nvrmini 2 os command injection vulnerabilitycgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary…EPSS 14%8.0CVE-2017-18861Netgear readynas surveillance cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects ReadyNAS Surveillance 1.4.3-15-x86 and earlier and ReadyNAS Surveillance 1.1.4-5-ARM and e…EPSS 0.38%7.5CVE-2016-5677Netgear readynas surveillance information exposure vulnerabilityNUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622…EPSS 12%7.5CVE-2016-5676NUUO NVR and NETGEAR ReadyNAS Surveillance admin password reset via improper authorizationThe cgi-bin/cgi_system endpoint in NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance accepts a cmd=loaddefconfig action that resets the admin…EPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2016-5675), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.