Unrestricted File Upload Vulnerability in NETGEAR Management System NMS300
CVE-2016-1524

9.6CRITICAL

Key Information:

Vendor
Netgear
Vendor
CVE Published:
13 February 2016

Summary

The NETGEAR Management System NMS300 contains multiple vulnerabilities that allow unauthorized file uploads. Attackers can exploit these flaws by uploading malicious JSP files through specific endpoints, such as fileUpload.do. Once uploaded, attackers may execute arbitrary Java code by directly accessing the file via a crafted URI. This vulnerability poses significant risks as it can lead to unauthorized system access and data compromise.

References

EPSS Score

71% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.