VDB
CVE-2016-1525
CVE-2016-1525
PUBLISHED
CVSS 7.800000190734863 HIGH
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the realName parameter.
EPSS 80.31% · 99.1th percentile
Risk Scores
CVSS 2.0
7.800000190734863
EPSS Score
80.31%
99.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| netgear | prosafe_network_management_software_300 | 1.5.0.11 |
| n/a | n/a | * |
Timeline
- Feb 3, 2016 CVE Published
- Feb 4, 2016 PoC Published
- Mar 1, 2016 PoC Published
- Mar 1, 2016 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
References
- http://www.rapid7.com/db/modules/exploit/windows/http/netgear_nms_rce url
- 20160204 [CERT 777024 / CVE-2016-1524/5]: RCE and file download in Netgear NMS300 mailing-list
- 20160204 [CERT 777024 / CVE-2016-1524/5]: RCE and file download in Netgear NMS300 mailing-list
- 39515 exploit
- http://packetstormsecurity.com/files/135618/Netgear-Pro-NMS-300-Code-Execution-File-Download.html url
- http://packetstormsecurity.com/files/135999/NETGEAR-ProSafe-Network-Management-System-300-Arbitrary-File-Upload.html url
- 39412 exploit
- VU#777024 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-1525 advisory
- https://www.exploit-db.com/exploits/39412 url
- https://www.exploit-db.com/exploits/39515 url