cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_license command.
2016-08-31T15:59:05.750
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nuuo | nvrmini_2 | 1.7.6 | Yes |
Operating System | nuuo | nvrmini_2 | 2.0.0 | Yes |
Operating System | nuuo | nvrmini_2 | 2.2.1 | Yes |
Operating System | nuuo | nvrmini_2 | 3.0.0 | Yes |
Application | netgear | readynas_surveillance | 1.1.2 | Yes |