Unrestricted File Upload Vulnerability in NETGEAR Management System NMS300
CVE-2016-1524
9.6CRITICAL
Key Information:
- Vendor
- Netgear
- Vendor
- CVE Published:
- 13 February 2016
Summary
The NETGEAR Management System NMS300 contains multiple vulnerabilities that allow unauthorized file uploads. Attackers can exploit these flaws by uploading malicious JSP files through specific endpoints, such as fileUpload.do. Once uploaded, attackers may execute arbitrary Java code by directly accessing the file via a crafted URI. This vulnerability poses significant risks as it can lead to unauthorized system access and data compromise.
References
EPSS Score
71% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved