← Vulnerability feed

Vulnerability record · CVE-2016-5678 · published 31 August 2016

CVE-2016-5678: Nuuo nvrmini 2 hard-coded credentials vulnerability

Nuuo · Nvrmini 2

NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.

9.8 CVSS 3.0 Critical EPSS 8.7% · top 5.0% CWE-798 · Hard-coded credentials
9.8CVSS 3.0 base score, v2 10.0
8.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-5678 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-5675NUUO and NETGEAR NVR software PHP code execution via NTPServer parameterhandle_daylightsaving.php in NUUO NVRmini 2, NVRsolo, Crystal, and NETGEAR ReadyNAS Surveillance fails to validate the NTPServer parameter, allowing …EPSS 71%analysed9.8CVE-2016-5674NUUO NVR and NETGEAR ReadyNAS Surveillance PHP code execution via log parameterThe __debugging_center_utils___.php script in NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance fails to validate the log parameter, allowing…EPSS 95%analysed8.8CVE-2016-5680Nuuo nvrmini 2 memory buffer overflow vulnerabilityStack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authentic…EPSS 17%8.8CVE-2016-5679Nuuo nvrmini 2 os command injection vulnerabilitycgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary…EPSS 14%7.5CVE-2016-5677Netgear readynas surveillance information exposure vulnerabilityNUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622…EPSS 12%7.5CVE-2016-5676NUUO NVR and NETGEAR ReadyNAS Surveillance admin password reset via improper authorizationThe cgi-bin/cgi_system endpoint in NUUO NVRmini 2, NVRsolo and NETGEAR ReadyNAS Surveillance accepts a cmd=loaddefconfig action that resets the admin…EPSS 54%analysed10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2016-5678), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.