Nvrmini 2
Vendor:
First CVE: Aug 31, 2016 · Active for 9 years
7
Total CVEs
More Total CVEs than 85% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nvrmini 2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2016
9 years ago
Most Recent CVE
Aug 31, 2016
3,618 days ago
CVE Severity & Scoring
Nvrmini 27 CVEs
57%
43%
All CVEs352,785 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5674CRITICAL __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attacke | Aug 31, 2016 | 9.8 | 93 | NO | YES |
CVE-2016-5675CRITICAL handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through | Aug 31, 2016 | 9.8 | 85 | NO | YES |
CVE-2016-5676HIGH cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the a | Aug 31, 2016 | 7.5 | 68 | NO | YES |
CVE-2016-5680HIGH Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary | Aug 31, 2016 | 8.8 | 47 | NO | YES |
CVE-2016-5679HIGH cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharact | Aug 31, 2016 | 8.8 | 46 | NO | YES |
CVE-2016-5677HIGH NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng ac | Aug 31, 2016 | 7.5 | 40 | NO | YES |
CVE-2016-5678CRITICAL NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecifi | Aug 31, 2016 | 9.8 | 38 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
42.9% of CVEs· 98th percentile
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
7 CVEs
100.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Nvrmini 2
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.0 | 7 | 8.9 | 38.7% | 0 | 7 |
| 2.2.1 | 7 | 8.9 | 38.7% | 0 | 7 |
| 2.0.0 | 7 | 8.9 | 38.7% | 0 | 7 |
| 1.7.6 | 7 | 8.9 | 38.7% | 0 | 7 |
| 1.7.5 | 5 | 8.9 | 48.0% | 0 | 5 |
| 1.7.2 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.7.1 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.7.0 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.6.4 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.6.2 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.6.1 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.6.0 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.5.2 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.5.1 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.4.0 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.3.2 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.3.0 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.1.0 | 1 | 9.8 | 8.7% | 0 | 1 |
| 1.0.0 | 1 | 9.8 | 8.7% | 0 | 1 |